AFL++
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
What AFL++ is
AFL++ (American Fuzzy Lop plus plus) is a fuzzer forked from Google's AFL. The fork changes its mutations and instrumentation and adds custom module support. Targets with source code are compiled with the afl-cc compiler wrapper and then run under afl-fuzz with a directory of seed inputs. Programs that read from stdin or from a file are both supported. Dictionaries can be supplied for verbose input formats such as SQL or HTTP. Crashes and hangs are written to subdirectories of the output directory for replay. The documentation also covers binary-only targets, network services and GUI programs. A Docker image with everything compiled is published for x86_64 and arm64.
Written from the project's README, read .
- Category
- Security testing
- License
- AGPL-3.0
- Language
- C
- Changelog
- Releases on GitHub
Repository metrics
Status
activeLast commit within 90 days of the fetch date.Computed from the last commit date and the archive flag on the fetch date. See the status rules.
Alternatives
Listed security testing tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from AFL++'s, with its source.
Honggfuzz: Scan targets: Programs, and APIs tested in-process (persistent fuzzing). source: README
sqlmap: Scan targets: Web application parameters: GET, POST, cookie, User-Agent and Referer values. source: Docs: Features
Trivy: Scan targets: Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes. source: README
Nuclei: Scan targets: Target URLs and hosts, from a single target or a list file. source: README
Gitleaks: Scan targets: Secrets such as passwords, API keys and tokens in git repositories, files and stdin. source: README
Promptfoo: Scan targets: LLM apps, through red teaming and vulnerability scanning. source: README
ffuf: Scan targets: Web servers: content paths, virtual hosts, GET parameters and POST data. source: README
ZAP: Scan targets: Web applications. source: README
How to install
docker pull aflplusplus/aflplusplusQuestions
Is AFL++ open source?
Yes. AFL++ is released under AGPL-3.0, an OSI-approved license, as reported by the GitHub API on 2026-09-22.
Is AFL++ maintained?
On 2026-09-22, the last commit to the default branch was on 2026-09-02, so the listed status is active. Rule: Last commit within 90 days of the fetch date.
How many GitHub stars does AFL++ have?
6,765 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.
What language is AFL++ written in?
The repository's primary language, as reported by the GitHub API, is C.
How do I install AFL++?
The README gives this command: docker pull aflplusplus/aflplusplus
Sources
- GitHub REST API: repository, read
- GitHub REST API: commits, read
- GitHub REST API: latest release, read
- GitHub REST API: contributors, read
- README, read