SSTImap is an automated detection tool that identifies Server-Side Template Injection (SSTI) vulnerabilities in web applications. The tool provides an interactive interface for security professionals to systematically test web applications for template injection flaws. It automates the vulnerability detection process by analyzing server responses and identifying potential injection points across various template engines. SSTImap supports multiple web application frameworks and can detect different types of template injection vulnerabilities. The interactive interface allows users to configure testing parameters and review detailed assessment results. The tool is designed for penetration testers, security researchers, and application security professionals conducting security assessments and code reviews to identify template injection vulnerabilities.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
A modular Python tool that obfuscates Android applications by manipulating decompiled smali code, resources, and manifest files without requiring source code access.
A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
An open-source tool that automates the detection and analysis of DLL hijacking vulnerabilities in Windows applications, providing detailed reports and remediation guidance.
Search engine for open-source Git repositories with advanced features like case sensitivity and regular expressions.
ThreatLocker is an enterprise cybersecurity platform that provides comprehensive endpoint protection and zero-trust security to prevent ransomware, viruses, and other malicious software from running on endpoints.
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.