Skip to content
View mohammadsec's full-sized avatar

Block or report mohammadsec

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

103 stars written in JavaScript
Clear filter

30 days of JavaScript programming challenge is a step-by-step guide to learn JavaScript programming language in 30 days. This challenge may take more than 100 days, please just follow your own pace…

JavaScript 46,194 10,440 Updated Dec 6, 2025

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…

JavaScript 20,666 3,624 Updated Mar 22, 2026

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,779 828 Updated Mar 21, 2026

CF-workers/pages代理脚本:支持Vless-ws(tls)、Trojan-ws(tls);Socks5/http本地代理脚本:可选ECH-TLS、普通TLS、无TLS三种代理模式

JavaScript 13,732 9,034 Updated Mar 18, 2026

JavaScript parser / mangler / compressor / beautifier toolkit

JavaScript 13,411 1,231 Updated Nov 22, 2024

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 12,081 3,402 Updated Mar 22, 2026

Running V2ray inside edge/serverless runtime

JavaScript 8,307 42,002 Updated Nov 27, 2024

Awesome XSS stuff

JavaScript 5,073 776 Updated Oct 30, 2024

🔥🔥 hooker is a Frida-based reverse engineering toolkit for Android. It offers a user-friendly CLI, universal scripts, auto hook generation, memory roaming to detect activities/services, one-click S…

JavaScript 5,023 1,247 Updated Mar 16, 2026

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript 4,093 435 Updated Mar 22, 2026

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

JavaScript 3,947 483 Updated Feb 28, 2025

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

JavaScript 3,850 805 Updated Mar 20, 2026

pull decrypted ipa from jailbreak device

JavaScript 3,818 709 Updated May 3, 2023

This GitHub repo is a powerhouse collection of scraping APIs for developers that you can start using immediately to build everything from simple automations to full-scale applications.

JavaScript 3,090 531 Updated Jan 20, 2026

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

JavaScript 2,988 404 Updated Mar 18, 2026

Hand-crafted Frida examples

JavaScript 2,519 439 Updated Nov 29, 2024

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

JavaScript 2,328 217 Updated Nov 29, 2024

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

JavaScript 2,289 414 Updated Mar 7, 2024

Mobile Edge-Dynamic Unified Security Analysis

JavaScript 2,199 296 Updated Mar 19, 2026

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

JavaScript 2,032 270 Updated Mar 20, 2026

A container repository for my public web hacks!

JavaScript 2,020 274 Updated Oct 12, 2022

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

JavaScript 1,676 356 Updated May 24, 2025

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

JavaScript 1,550 182 Updated Jan 16, 2026

The XSS Hunter service - a portable version of XSSHunter.com

JavaScript 1,543 306 Updated Dec 7, 2022

A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python.

JavaScript 1,461 233 Updated Jun 3, 2021

XSS payloads designed to turn alert(1) into P1

JavaScript 1,394 228 Updated Sep 12, 2023

A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon

JavaScript 1,297 191 Updated Jan 26, 2024

PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.

JavaScript 1,294 120 Updated Aug 7, 2024

A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

JavaScript 1,139 175 Updated Mar 16, 2026

A cross-platform note-taking & target-tracking app for penetration testers.

JavaScript 916 133 Updated Jan 17, 2023
Next