# xl7dev/WebShell

Webshell && Backdoor Collection

Repository: https://github.com/xl7dev/WebShell
Canonical: https://ross.abutalabs.com/products/xl7dev-webshell
Homepage: http://blog.safebuff.com/WebShell/
Language: PHP
License: GPL-2.0
License Family: copyleft
Topics: webshell, shell, rootkit, backdoor
Last push: 2020-04-06T15:58:22+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3974, "days_push": 2340, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2009, forks 1028 (observed 2026-08-28T04:06:04.920015+00:00)

## What it is
A curated collection of webshells and backdoors written in many languages (PHP, ASP, JSP, Python, etc.) for security research and penetration testing. It aggregates samples across categories like tunneling tools, rootkits, and server-specific shells.

## Use cases
- find webshell samples for malware research
- build detection signatures for webshells
- test WAF and antivirus detection of backdoors
- red team tooling reference during penetration tests
- study webshell techniques across languages

## When to choose
- you need a broad reference corpus of webshell samples for research or detection
- you are doing authorized penetration testing and need shell payloads

## When to avoid
- you want a maintained tool with active development
- you need a defensive scanning product rather than raw samples
- unauthorized use - this is dual-use material

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, reverse-engineering
- domain: security, penetration-testing, developer-tools
- platform: cross-platform
- tags: webshell, backdoor, red-team, php, collection, offensive-security, web-server

## Member repositories
- xl7dev/WebShell (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:04.920015+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:01:16.531007+00:00, confidence not recorded.
  - readme: https://github.com/xl7dev/WebShell (fetched 2026-08-28T04:06:04.920015+00:00, sha 7a1d9496cd9b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
