Ross ROSS = Recommend OSS · open-source software intelligence for agents

smxiazi/xia_sql

xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。 observed · 2026-08-28

github.com/smxiazi/xia_sql · Java observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1666
  • days_rel: n/a
  • days_push: 1203
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1286 stars · 85 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Burp Suite extension (written in Java) that appends single and double quotes to every request parameter to detect possible SQL injection, flagging length differences and database error keywords for manual review. It supports JSON nested parameters, cookies, custom payloads, time-based blind injection hints, and Proxy/Repeater traffic monitoring.

Use cases

  • detect sql injection in burp proxy traffic
  • test request parameters for injection with quote payloads
  • find database error messages in http responses
  • scan json nested parameters for sql injection
  • test cookies for sql injection
  • run custom payloads for time-based blind injection

When to choose

  • you want a lightweight, quick-pass SQL injection hint tool inside Burp Suite
  • you prefer manual verification of injection findings over fully automated scanners
  • you need to test JSON, cookies, or numeric parameters with simple quote payloads

When to avoid

  • you need comprehensive automated SQL injection testing with full exploit capabilities
  • you want a standalone scanner outside Burp Suite
  • you require guaranteed compatibility with the latest Burp/JDK versions without rebuilding

Facets

plugin · maturity maintenance

penetration-testing security developer-tools security penetration-testing web-development developer-tools jvm cross-platform burp-suite-extension sql-injection vulnerability-scanning web-security manual-testing

1 source

Member repositories

RepositoryRoleHealth v2
smxiazi/xia_sqlmain23

For agents

markdown · JSON · MCP: product_card(name="smxiazi/xia_sql")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem