Ross ROSS = Recommend OSS · open-source software intelligence for agents

xmendez/wfuzz

Web application fuzzer observed · 2026-08-28

github.com/xmendez/wfuzz · homepage · Python · GPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

60/100

  • Activity 63
  • Release rhythm 34
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4333
  • days_rel: 224
  • days_push: 224
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

6558 stars · 1398 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable payloads. It supports fuzzing parameters, headers, directories, forms, and authentication, and includes a plugin-based vulnerability scanner.

Use cases

  • brute-force directories and files on a web server
  • fuzz HTTP parameters to find injection vulnerabilities
  • discover hidden endpoints during a web app pentest
  • brute-force login forms and authentication
  • fuzz HTTP headers for security testing
  • replay and modify requests captured from Burp Suite

When to choose

  • you need a scriptable CLI fuzzer for web security assessments
  • you want to inject payloads into any part of an HTTP request
  • you prefer a modular Python tool you can extend with plugins

When to avoid

  • you need a modern actively developed alternative like ffuf or feroxbuster
  • you want a GUI web vulnerability scanner
  • you need non-HTTP protocol fuzzing

Facets

cli-tool · maturity maintenance

penetration-testing http-client security web-scraping security penetration-testing web-development python cli windows web-fuzzer fuzzing wordlists burp-suite vulnerability-scanning http-requests command-line linux macos docker

2 sources

Member repositories

RepositoryRoleHealth v2
xmendez/wfuzzmain60

For agents

markdown · JSON · MCP: product_card(name="xmendez/wfuzz")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem