Ross ROSS = Recommend OSS · open-source software intelligence for agents

epinna/weevely3

Weaponized web shell observed · 2026-08-28

github.com/epinna/weevely3 · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

46/100

  • Activity 44
  • Release rhythm 18
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4365
  • days_rel: 336
  • days_push: 336
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

3533 stars · 624 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Weevely is a weaponized web shell for post-exploitation that generates a small obfuscated PHP agent to upload to a target web server, providing remote shell access over HTTP. It includes 30+ modules for privilege escalation, file management, SQL pivoting, port scanning, and network spreading.

Use cases

  • generate a stealthy php web shell for a pentest
  • get remote shell access to a compromised web server
  • maintain persistence on a target host during post-exploitation
  • pivot through a web server to scan internal network
  • bruteforce sql credentials on a target
  • bypass php disable_function restrictions
  • tunnel http traffic through a target server

When to choose

  • you need a stealthy, extensible web shell for authorized penetration testing
  • you want post-exploitation modules (privilege escalation, pivoting, file ops) in one tool
  • you need communication obfuscated within normal HTTP requests to evade AV detection

When to avoid

  • you need a general-purpose reverse shell framework without a web server entry point
  • you want a defensive tool for detecting or removing web shells
  • unauthorized use - this is an offensive security tool for legal engagements only

Facets

cli-tool · maturity active

security penetration-testing http-client cli security penetration-testing developer-tools python cli windows web-shell post-exploitation php-agent red-team offensive-security remote-shell command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
epinna/weevely3main46

For agents

markdown · JSON · MCP: product_card(name="epinna/weevely3")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem