Suggest a tool

ffuf alternatives: 8 open-source security testing tools

Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.

About ffuf

ffuf is a listed security testing tool: Go command-line web fuzzer for content, virtual host and parameter discovery using wordlists.

Order: Listed tools in the same category, with tools in the same primary language (GitHub API) first, then by GitHub stars. Each line gives one fact from the tool's own documentation where it differs from what ffuf's documentation states, with its source.

8 alternatives to ffuf

Repository metrics

ffuf and its alternatives. Sorted by GitHub stars, descending, descending. Select a column heading to change the sort.
sqlmap38,49212026-01-0111.102026-09-201GPL-2.0-or-laterPythonactive
Trivy38,00912026-08-141v0.74.02026-09-221Apache-2.0Goactive
Nuclei31,43112026-08-081v3.11.12026-09-221MITGoactive
Gitleaks29,42812026-03-211v8.30.12026-07-221MITGoactive
Promptfoo25,37112026-09-1810.123.12026-09-221MITTypeScriptactive
ffuf16,70312026-09-091v2.3.02026-09-091MITGoactive
ZAP15,80412025-12-151v2.17.02026-09-171Apache-2.0Javaactive
OSV-Scanner11,07312026-09-141v2.6.02026-09-221Apache-2.0Goactive
Nikto10,73612026-07-3112.6.12026-08-151GPL-3.0-onlyPerlactive

1 Fetched from the GitHub or GitLab API on . Hover a value for its own date.