CakeFuzzer is an automated vulnerability discovery tool designed for web applications built on the CakePHP framework. The tool operates continuously to identify security vulnerabilities in CakePHP-based applications while maintaining a focus on reducing false positive results. It specifically targets applications developed using the Cake PHP framework architecture. The project includes research documentation and maintains records of reported bugs through the CakePHP Application Cybersecurity Research article series. This documentation provides insights into the research methodology and vulnerability discovery process. CakeFuzzer aims to streamline the security testing process for CakePHP applications by providing automated scanning capabilities tailored to the framework's specific characteristics and common vulnerability patterns.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
An open-source tool that automates the detection and analysis of DLL hijacking vulnerabilities in Windows applications, providing detailed reports and remediation guidance.
A technology lookup and lead generation tool that identifies the technology stack of any website and provides features for market research, competitor analysis, and data enrichment.
A Nuxt 3 security module that automatically implements OWASP security patterns through HTTP headers, middleware, and various protection mechanisms including CSP, XSS validation, CORS, and CSRF protection.
A deliberately vulnerable Java web application designed for educational purposes to teach web application security concepts and common vulnerabilities.
A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.
Bearer CLI is a static application security testing tool that scans source code across multiple programming languages to identify and prioritize OWASP Top 10 and CWE Top 25 security vulnerabilities through data flow analysis.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
A modular Python tool that obfuscates Android applications by manipulating decompiled smali code, resources, and manifest files without requiring source code access.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.