Open source bugbounty-tool projects

Every project in the registry tagged bugbounty-tool, ranked by real GitHub adoption.

projects 3 combined stars ★ 14K refresh nightly
01 reconftw ★ 8.2K

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

last push7 days ago languageShell licenseMIT
02 malicious-pdf ★ 4.4K

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and w

last push1 months ago languagePython licenseBSD-2-Clause
03 inql ★ 1.8K

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Bu

last push23 days ago languageKotlin licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source bugbounty-tool projects are there?

This registry tracks 3 projects tagged bugbounty-tool, with 14,423 GitHub stars between them. The most-adopted is reconftw at 8,164 stars.

Are these bugbounty-tool projects free to use?

Yes — 3 of the 3 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which bugbounty-tool project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these bugbounty-tool projects still maintained?

3 of the 3 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.