karthikuj/sasori

Sasori is a dynamic web crawler powered by Puppeteer, designed for lightning-fast endpoint discovery.

40
/ 100
Emerging

Sasori helps security engineers and penetration testers automatically map out the attack surface of web applications, including modern dynamic sites and those behind login screens. It takes a starting URL and optional recorded login steps, then interacts with the site to discover all accessible pages and endpoints. The output is a comprehensive list of URLs and their associated structures, which can be fed into security scanners like Zaproxy or Burp Suite.

145 stars. No commits in the last 6 months.

Use this if you need to thoroughly explore a web application to find all its hidden pages, forms, and functionalities for security assessment, especially if it uses modern JavaScript or requires authentication.

Not ideal if you're only looking to scrape static content from a few known pages or build a simple data collection bot, as its focus is on comprehensive endpoint discovery for security.

penetration-testing web-application-security attack-surface-mapping vulnerability-discovery security-audit
Stale 6m No Package No Dependents
Maintenance 0 / 25
Adoption 10 / 25
Maturity 16 / 25
Community 14 / 25

How are scores calculated?

Stars

145

Forks

16

Language

JavaScript

License

MIT

Last pushed

Jul 23, 2024

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/perception/karthikuj/sasori"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.