h4r5h1t/webcopilot
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities. observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1830
- days_rel: n/a
- days_push: 776
- n_releases_24m: 0
Adoption not part of the score
1295 stars · 203 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters parameters vulnerable to XSS, SQLi, open redirect, LFI, SSRF, and RCE, and scans for vulnerabilities with tools like dalfox and nuclei. It orchestrates a pipeline of open-source security tools and saves all output to a specified directory.
Use cases
- automate subdomain enumeration for a target domain
- find XSS and SQLi parameters across subdomains
- run a full recon and vulnerability scan pipeline for bug bounty
- check for subdomain takeover
- crawl endpoints from wayback and filter by vulnerability patterns
- scan a domain for SSRF, LFI, and open redirect bugs
When to choose
- you want a one-command recon-to-vuln-scan pipeline for bug bounty targets
- you already use tools like subfinder, amass, httpx, and nuclei and want them chained automatically
- you need organized output files from a multi-tool recon workflow
When to avoid
- you need a maintained, production-grade vulnerability scanner with support
- you are on Windows without WSL or a Unix-like shell
- you want a GUI or interactive web interface
- you need authorized enterprise security testing with reporting features
Facets
cli-tool · maturity active
security penetration-testing web-scraping cli workflow-automation security penetration-testing developer-tools cli bug-bounty recon subdomain-enumeration vulnerability-scanning reconnaissance bash-script offensive-security command-line linux macos
1 source
- readme: https://github.com/h4r5h1t/webcopilot · fetched 2026-08-28 · 3675314f2b26
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| h4r5h1t/webcopilot | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="h4r5h1t/webcopilot")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem