# Moham3dRiahi/XAttacker

X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

Repository: https://github.com/Moham3dRiahi/XAttacker
Canonical: https://ross.abutalabs.com/products/xattacker
Language: Perl
License Family: other
Topics: vulnerability-scanner, vulnerability-detection, vulnerability-exploit, vulnerability-assessment, security-scanner, scanner, security-tools, website-vulnerability-scanner, hacking, hacking-tool, pentest, wp-scanner, wordpress, prestashop, joomla, lokomedia, drupal, auto-exploiter, exploit, exploitation
Last push: 2023-10-08T21:45:25+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3221, "days_push": 1060, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1757, forks 468 (observed 2026-08-28T04:05:32.339895+00:00)

## What it is
XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target's CMS (WordPress, Joomla, Drupal, PrestaShop, Lokomedia) and attempts known exploits against it, reporting exploit links to the user.

## Use cases
- scan a website for known CMS vulnerabilities
- auto-exploit vulnerable WordPress plugins
- test a list of websites for exploitable CMS flaws
- detect which CMS a target site runs
- find exploitable Joomla or Drupal components
- generate plain-text reports of found vulnerabilities

## When to choose
- you need a quick automated scanner plus exploiter for common CMS vulnerabilities in a lab or authorized pentest
- you want a lightweight Perl script with no complex dependencies
- you are testing many targets from a list at once

## When to avoid
- you need a modern, maintained scanner with CVE database integration
- you require a license-compliant tool for commercial use (no license is provided)
- you need stealth, depth, or accuracy beyond known public CMS exploits
- you lack explicit authorization to test the target

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: vulnerability-scanning, penetration-testing, security
- domain: security, penetration-testing, web-development
- platform: cli, windows
- tags: auto-exploiter, cms-vulnerabilities, wordpress, joomla, drupal, prestashop, perl, hacking-tool, educational, linux, macos

## Member repositories
- Moham3dRiahi/XAttacker (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:32.339895+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:27:38.364676+00:00, confidence not recorded.
  - readme: https://github.com/Moham3dRiahi/XAttacker (fetched 2026-08-28T04:05:32.339895+00:00, sha fb5a85bdcf9c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
