Follow me on GitHub: https://github.com/TrixSec
And also Fork and star the waymap repo : https://github.com/TrixSec/waymap
And also Fork and star the waymap repo : https://github.com/TrixSec/waymap
GitHub
TrixSec - Overview
~. TrixSec has 43 repositories available. Follow their code on GitHub.
WAYMAP New Update - v6.2.8 ππ- Added Time Based Sqli Scanning Logic- Added Scan Results Saving Logic- Added Interactive Prompt Based and Argument Based Scanning Logic- Updated The UI
Try Out
https://github.com/TrixSec/waymapWAYMAP New Update - v6.2.9 ππ- Bug Fixed- Optimised- Reduced Lag
Try Out
https://github.com/TrixSec/waymapπ₯ New Tool Release: HexaCloner π₯
Clone any website with advanced options, blazing speed, and a beautiful CLI!
Selective resource cloning
Resume support
Authentication
Progress bar & colored output
Cross-platform
Get it now:
π https://github.com/TrixSec/HexaCloner
By Trix Cyrus (@TrixSec)
#opensource #python #webtools
Clone any website with advanced options, blazing speed, and a beautiful CLI!
Selective resource cloning
Resume support
Authentication
Progress bar & colored output
Cross-platform
Get it now:
π https://github.com/TrixSec/HexaCloner
By Trix Cyrus (@TrixSec)
#opensource #python #webtools
π₯5β€2
π WAYMAP v7.0.0 - MAJOR RELEASE! π
π The biggest update yet is here!
We're thrilled to announce Waymap v7.0.0 - a complete UI/UX overhaul that makes vulnerability scanning more professional and consistent than ever before!
ββββββββββββββββββββββββββ
β¨ WHAT'S NEW
π¨ Complete UI Standardization
β’ All 15 scan modules now have consistent formatting
β’ Professional cyan headers across all scans
β’ Standardized icons and color scheme:
[β’] Cyan - Information
[β] Green - Vulnerabilities
[β οΈ] Yellow - Warnings
[β] Red - Errors
[βοΈ] Blue - Debug output
π Critical Bug Fixes
β’ Fixed JSON structure crashes
β’ Resolved circular import issues
β’ Fixed result saving across all modules
β’ Enhanced threading consistency
β’ Graceful exit handling everywhere
π§ Enhanced Features
β’ Verbose mode for detailed debugging
β’ Consistent user prompts
β’ Proper completion messages
β’ Better error handling
β’ Improved threading performance
ββββββββββββββββββββββββββ
π¦ 15 MODULES STANDARDIZED
β Injection Scans (7)
LFI β’ CMDi β’ SSTI β’ CRLF β’ CORS β’ Open Redirect β’ XSS
β SQL Injection (3)
Boolean-based β’ Error-based β’ Time-based
β Profile Scans (3)
High-Risk β’ Critical-Risk β’ Deep Scan
ββββββββββββββββββββββββββ
β‘οΈ INSTALL NOW
Or upgrade:
ββββββββββββββββββββββββββ
π LINKS
π¦ PyPI: https://pypi.org/project/waymap/7.0.0/
π GitHub: https://github.com/TrixSec/waymap
π Docs: https://github.com/TrixSec/waymap/blob/main/README.md
ββββββββββββββββββββββββββ
π‘ QUICK START
ββββββββββββββββββββββββββ
π― WHY UPGRADE?
Before v7.0.0:
β Inconsistent output formatting
β Different colors for different scans
β Varying prompt styles
β Result saving bugs
After v7.0.0:
β 100% Consistent UI/UX
β Professional output
β Reliable performance
β Production ready
ββββββββββββββββββββββββββ
π 75+ WEB VULNERABILITIES
Waymap can scan for over 75 different web vulnerabilities including:
β’ SQL Injection (All types)
β’ XSS (Cross-Site Scripting)
β’ Command Injection
β’ SSTI (Template Injection)
β’ LFI (File Inclusion)
β’ CORS Misconfigurations
β’ CRLF Injection
β’ Open Redirects
β’ CMS-specific CVEs
β’ And much more!
ββββββββββββββββββββββββββ
π₯ FEATURES
β Multi-threaded scanning
β Profile-based scans (High-Risk, Critical, Deep)
β WAF/IPS detection (160+ types)
β Automated crawling
β Result saving in JSON
β No-prompt mode for automation
β Verbose debugging mode
β CMS detection (WordPress, Drupal)
ββββββββββββββββββββββββββ
π¨βπ» DEVELOPED BY
Trix Cyrus (Vicky)
Β© 2024-25 Trixsec Org
ββββββββββββββββββββββββββ
βοΈ SUPPORT THE PROJECT
Star us on GitHub: https://github.com/TrixSec/waymap
Report issues: https://github.com/TrixSec/waymap/issues
ββββββββββββββββββββββββββ
π This is our most polished release yet!
Every scan module has been carefully standardized to provide you with a professional, consistent experience. Whether you're a penetration tester, security researcher, or ethical hacker - Waymap v7.0.0 is ready for production use!
Install now and experience the difference!
#Waymap #WebSecurity #VulnerabilityScanner #PenTesting #EthicalHacking #CyberSecurity #InfoSec #BugBounty #SecurityTools #TrixSec
ββββββββββββββββββββββββββ
π¬ Join our community:
π± Telegram: @Trixsec
π GitHub: TrixSec/waymap
Happy Hacking! π―
π The biggest update yet is here!
We're thrilled to announce Waymap v7.0.0 - a complete UI/UX overhaul that makes vulnerability scanning more professional and consistent than ever before!
ββββββββββββββββββββββββββ
β¨ WHAT'S NEW
π¨ Complete UI Standardization
β’ All 15 scan modules now have consistent formatting
β’ Professional cyan headers across all scans
β’ Standardized icons and color scheme:
[β’] Cyan - Information
[β] Green - Vulnerabilities
[β οΈ] Yellow - Warnings
[β] Red - Errors
[βοΈ] Blue - Debug output
π Critical Bug Fixes
β’ Fixed JSON structure crashes
β’ Resolved circular import issues
β’ Fixed result saving across all modules
β’ Enhanced threading consistency
β’ Graceful exit handling everywhere
π§ Enhanced Features
β’ Verbose mode for detailed debugging
β’ Consistent user prompts
β’ Proper completion messages
β’ Better error handling
β’ Improved threading performance
ββββββββββββββββββββββββββ
π¦ 15 MODULES STANDARDIZED
β Injection Scans (7)
LFI β’ CMDi β’ SSTI β’ CRLF β’ CORS β’ Open Redirect β’ XSS
β SQL Injection (3)
Boolean-based β’ Error-based β’ Time-based
β Profile Scans (3)
High-Risk β’ Critical-Risk β’ Deep Scan
ββββββββββββββββββββββββββ
β‘οΈ INSTALL NOW
pip install waymap==7.0.0
Or upgrade:
pip install --upgrade waymap
ββββββββββββββββββββββββββ
π LINKS
π¦ PyPI: https://pypi.org/project/waymap/7.0.0/
π GitHub: https://github.com/TrixSec/waymap
π Docs: https://github.com/TrixSec/waymap/blob/main/README.md
ββββββββββββββββββββββββββ
π‘ QUICK START
# Basic scan
waymap --target https://example.com --scan xss
# Profile scan
waymap --target https://example.com --profile high-risk
# Verbose mode
waymap --target https://example.com --scan sqli --verbose
ββββββββββββββββββββββββββ
π― WHY UPGRADE?
Before v7.0.0:
β Inconsistent output formatting
β Different colors for different scans
β Varying prompt styles
β Result saving bugs
After v7.0.0:
β 100% Consistent UI/UX
β Professional output
β Reliable performance
β Production ready
ββββββββββββββββββββββββββ
π 75+ WEB VULNERABILITIES
Waymap can scan for over 75 different web vulnerabilities including:
β’ SQL Injection (All types)
β’ XSS (Cross-Site Scripting)
β’ Command Injection
β’ SSTI (Template Injection)
β’ LFI (File Inclusion)
β’ CORS Misconfigurations
β’ CRLF Injection
β’ Open Redirects
β’ CMS-specific CVEs
β’ And much more!
ββββββββββββββββββββββββββ
π₯ FEATURES
β Multi-threaded scanning
β Profile-based scans (High-Risk, Critical, Deep)
β WAF/IPS detection (160+ types)
β Automated crawling
β Result saving in JSON
β No-prompt mode for automation
β Verbose debugging mode
β CMS detection (WordPress, Drupal)
ββββββββββββββββββββββββββ
π¨βπ» DEVELOPED BY
Trix Cyrus (Vicky)
Β© 2024-25 Trixsec Org
ββββββββββββββββββββββββββ
βοΈ SUPPORT THE PROJECT
Star us on GitHub: https://github.com/TrixSec/waymap
Report issues: https://github.com/TrixSec/waymap/issues
ββββββββββββββββββββββββββ
π This is our most polished release yet!
Every scan module has been carefully standardized to provide you with a professional, consistent experience. Whether you're a penetration tester, security researcher, or ethical hacker - Waymap v7.0.0 is ready for production use!
Install now and experience the difference!
pip install waymap==7.0.0
#Waymap #WebSecurity #VulnerabilityScanner #PenTesting #EthicalHacking #CyberSecurity #InfoSec #BugBounty #SecurityTools #TrixSec
ββββββββββββββββββββββββββ
π¬ Join our community:
π± Telegram: @Trixsec
π GitHub: TrixSec/waymap
Happy Hacking! π―
GitHub
GitHub - TrixSec/waymap: Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifyingβ¦
Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads. - TrixSec/waymap
π1π₯1
Trixsec pinned Β«π WAYMAP v7.0.0 - MAJOR RELEASE! π π The biggest update yet is here! We're thrilled to announce Waymap v7.0.0 - a complete UI/UX overhaul that makes vulnerability scanning more professional and consistent than ever before! ββββββββββββββββββββββββββ β¨β¦Β»
v7.1.0 - API Security, Auth & Reporting π
Release Date: December 2024
Fast, Optimized, and Comprehensive Web Vulnerability Scanner
Waymap v7.1.0 introduces powerful new capabilities for API security testing, advanced authentication, and professional reporting.
π What's New?
π API Security Testing
REST API Scanning: Test endpoints for missing auth, IDOR, and rate limiting.
GraphQL Support: Detect introspection, query depth issues, and schema exposure.
Method Testing: Automated testing of GET, POST, PUT, DELETE, PATCH methods.
π Advanced Authentication
Multi-Protocol Support: Form-based, HTTP Basic, Digest, Bearer Token, and API Key.
Session Management: Maintain authenticated sessions across scans.
Custom Headers: Inject custom authentication headers.
π Professional Reporting
HTML Reports: Interactive dashboards with charts and detailed findings.
CSV Exports: Spreadsheet-compatible data for analysis.
Markdown: Documentation-ready reports.
PDF Reports: Professional PDF summaries.
Release Date: December 2024
Fast, Optimized, and Comprehensive Web Vulnerability Scanner
Waymap v7.1.0 introduces powerful new capabilities for API security testing, advanced authentication, and professional reporting.
π What's New?
π API Security Testing
REST API Scanning: Test endpoints for missing auth, IDOR, and rate limiting.
GraphQL Support: Detect introspection, query depth issues, and schema exposure.
Method Testing: Automated testing of GET, POST, PUT, DELETE, PATCH methods.
π Advanced Authentication
Multi-Protocol Support: Form-based, HTTP Basic, Digest, Bearer Token, and API Key.
Session Management: Maintain authenticated sessions across scans.
Custom Headers: Inject custom authentication headers.
π Professional Reporting
HTML Reports: Interactive dashboards with charts and detailed findings.
CSV Exports: Spreadsheet-compatible data for analysis.
Markdown: Documentation-ready reports.
PDF Reports: Professional PDF summaries.
GitHub
GitHub - TrixSec/waymap: Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifyingβ¦
Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads. - TrixSec/waymap
β€1
Search for Vulnerability π‘
SearchSploit
Dorks
Vulnerable Scan π―
WhatWeb
Golismero
Nikto
Nmap
HTTP Enumerating π
βοΈBrute-force , check http , https website ,enumerate one by one
βοΈDefault login for service or application , check reset password
βοΈCheck Default credentials for software
βοΈSQL-injectable GET/POST params
βοΈLFI/RFI through
βοΈ Check
βοΈ Heartbleed / CRIME find out potential correct vhost to GET , any names that could be usernames for bruteforce/guessing
Xprobe2 OS fingerprinting π£
SearchSploit
sudo apt-get install exploitdb
searchsploit xxx | grep linux
Dorks
site:exploit-db.com APP VERSION
site:rapid7.com "set TARGET" Sendmail
site:rapid7.com "use auxiliary" MSSQL
search type:exploit port:139
search samba type:exploit port:445
Vulnerable Scan π―
WhatWeb
whatweb <ip>
Golismero
golismero SCAN <ip>
Nikto
nikto -h <ip> -p 1234 <ip>
nikto -C all -h <ip> -p 80
nikto -C all -h <ip> -p 443
Nmap
nmap -v -sS -sV --script=vulscan.nse --script-args vulscandb=exploitdb.csv <ip>
nmap -sS -sV --script=vulscan.nse --script-args vulscandb=exploitdb.csv -p80 <ip>
nmap -sV --script=vuln <ip>
nmap -PN -sS -sV --script=all --script-args vulscancorrelation=1 <ip>
HTTP Enumerating π
βοΈBrute-force , check http , https website ,enumerate one by one
βοΈDefault login for service or application , check reset password
βοΈCheck Default credentials for software
βοΈSQL-injectable GET/POST params
βοΈLFI/RFI through
?page=foo type params /etc/passwd , ../../../../../boot.iniβοΈ Check
config.php and get sql loginβοΈ Heartbleed / CRIME find out potential correct vhost to GET , any names that could be usernames for bruteforce/guessing
Xprobe2 OS fingerprinting π£
xprobe2 -v -p tcp:80:open <ip>
β€1
π Waymap v7.2.1 Released
This release focuses on stability, reliability, and security hardening.
Highlights
β’ Thread-safe result saving with the new ResultManager
β’ Secure XML parsing using
β’ Improved time-based SQLi baseline to reduce false positives
β’ Fixed boolean and error-based SQLi detection
β’ Improved CRLF detection (headers + body)
β’ Open Redirect now works on Windows (no curl required)
β’ Fixed CMDi query-string handling
β’ Report loading fixed across all output formats
β’ Fixed WAF module imports and project path resolution
β’ Improved Windows Unicode support
All 12+ scanner modules have been updated to use the centralized ResultManager for safer, more reliable scanning.
Install
π¦ PyPI: https://pypi.org/project/waymap/7.2.1/
π» GitHub: https://github.com/TrixSec/waymap
If Waymap has been useful to you, consider starring the repository. It helps the project grow.
This release focuses on stability, reliability, and security hardening.
Highlights
β’ Thread-safe result saving with the new ResultManager
β’ Secure XML parsing using
defusedxml (XXE protection)β’ Improved time-based SQLi baseline to reduce false positives
β’ Fixed boolean and error-based SQLi detection
β’ Improved CRLF detection (headers + body)
β’ Open Redirect now works on Windows (no curl required)
β’ Fixed CMDi query-string handling
β’ Report loading fixed across all output formats
β’ Fixed WAF module imports and project path resolution
β’ Improved Windows Unicode support
All 12+ scanner modules have been updated to use the centralized ResultManager for safer, more reliable scanning.
Install
pip install waymap==7.2.1
π¦ PyPI: https://pypi.org/project/waymap/7.2.1/
π» GitHub: https://github.com/TrixSec/waymap
If Waymap has been useful to you, consider starring the repository. It helps the project grow.
PyPI
waymap
Advanced Web Application Security Scanner
π Waymap v8.0.0 is now available!
This is the biggest Waymap release so far.
What's new?
β’ AI-powered vulnerability analysis
β’ AI adaptive payload generation
β’ AI attack surface discovery
β’ AI false positive reduction
β’ AI vulnerability chain analysis
β’ Union, Inline and Stacked SQLi techniques
β’ Database enumeration
β’ Event-driven architecture
β’ Improved crawler
β’ Better reconnaissance engine
β’ Fingerprint engine for request deduplication
β’ Enhanced HTTP performance and reliability
Waymap continues to use deterministic detection while AI assists with reasoning, prioritization, and analysis.
GitHub:
https://github.com/TrixSec/waymap
Feedback and bug reports are always appreciated.
Don't forget to STAR
This is the biggest Waymap release so far.
What's new?
β’ AI-powered vulnerability analysis
β’ AI adaptive payload generation
β’ AI attack surface discovery
β’ AI false positive reduction
β’ AI vulnerability chain analysis
β’ Union, Inline and Stacked SQLi techniques
β’ Database enumeration
β’ Event-driven architecture
β’ Improved crawler
β’ Better reconnaissance engine
β’ Fingerprint engine for request deduplication
β’ Enhanced HTTP performance and reliability
Waymap continues to use deterministic detection while AI assists with reasoning, prioritization, and analysis.
GitHub:
https://github.com/TrixSec/waymap
Feedback and bug reports are always appreciated.
Don't forget to STAR
GitHub
GitHub - TrixSec/waymap: Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifyingβ¦
Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads. - TrixSec/waymap
β€1
Trixsec pinned Β«π Waymap v8.0.0 is now available! This is the biggest Waymap release so far. What's new? β’ AI-powered vulnerability analysis β’ AI adaptive payload generation β’ AI attack surface discovery β’ AI false positive reduction β’ AI vulnerability chain analysis β’ Unionβ¦Β»