Skip to content
View cure53's full-sized avatar

Sponsors

@dcramer
@jgraph
@healthchecks
@hata6502
@openclaw
@cybozu

Block or report cure53

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,791 828 Updated Mar 23, 2026

A small collection of potentially useful contract templates

424 63 Updated Jan 5, 2026

rewrite constructor arguments, call DOMPurify, profit

JavaScript 74 8 Updated Mar 2, 2026

Use DOMPurify on server and client in the same way

TypeScript 567 16 Updated Mar 24, 2026

A manager for your secrets.

JavaScript 962 93 Updated Jul 13, 2024

Some public notes

1,278 76 Updated Jul 13, 2019

A toolset for reverse engineering and fuzzing Protobuf-based apps

Python 1,642 198 Updated Mar 18, 2026

Enumerate Typo3 version and extensions

Python 174 34 Updated Jul 2, 2024

A collection of JavaScript engine CVEs with PoCs

2,315 403 Updated Sep 3, 2019

SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

Python 2,986 265 Updated Jun 28, 2024

TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.

Java 1,656 243 Updated May 25, 2024

Write any JavaScript with 6 Characters: []()!+

JavaScript 8,580 680 Updated Mar 10, 2025

Rip web accessible (distributed) version control systems: SVN/GIT/HG...

Perl 1,777 316 Updated Jul 19, 2024

Smallest possible syntactically valid files of different types

HTML 2,288 196 Updated Jul 18, 2024

A weekly selection of the relevant Chromium and Firefox intents

272 2 Updated Jan 19, 2025

A Firefox extension for whitelist driven safe JavaScript execution.

JavaScript 80 16 Updated Jul 25, 2018

minimalistic secure XMPP client in OCaml

OCaml 255 19 Updated Oct 21, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 69,705 24,926 Updated Mar 24, 2026
Bikeshed 263 33 Updated Mar 24, 2026

Attack Surface Management Platform

Shell 9,618 2,040 Updated Feb 15, 2026

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

PHP 1,746 354 Updated Sep 12, 2020

user.js -- Firefox configuration hardening

JavaScript 2,871 234 Updated Oct 8, 2025
Java 34 10 Updated Aug 5, 2015

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/ ) and the Hackmanit G…

Java 491 116 Updated Oct 3, 2024

RIPS - A static source code analyser for vulnerabilities in PHP scripts

PHP 362 62 Updated May 21, 2016

Magic hashes – PHP hash "collisions"

828 103 Updated Mar 23, 2025

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript 4,094 435 Updated Mar 24, 2026

jPurify

JavaScript 64 9 Updated Feb 16, 2017
Next