ffuf
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
What ffuf is
ffuf is a web fuzzer written in Go. It substitutes wordlist entries for a FUZZ keyword placed in the URL, headers or POST body. Documented uses include directory discovery, virtual host discovery without DNS records, and GET parameter and POST data fuzzing. Responses can be filtered by status code, size, word count, line count or response time. Test cases can come from an external mutator command instead of a wordlist. Default options load from an ffufrc configuration file. Pressing Enter during a run opens an interactive mode for adjusting filters. Results can be saved as JSON, HTML, Markdown or CSV.
Written from the project's README, read .
- Category
- Security testing
- License
- MIT
- Language
- Go
- Changelog
- Releases on GitHub
Repository metrics
Status
activeLast commit within 90 days of the fetch date.Computed from the last commit date and the archive flag on the fetch date. See the status rules.
Alternatives
Listed security testing tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from ffuf's, with its source. See also ffuf alternatives.
Trivy: Scan targets: Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes. source: README
Nuclei: Scan targets: Target URLs and hosts, from a single target or a list file. source: README
Gitleaks: Scan targets: Secrets such as passwords, API keys and tokens in git repositories, files and stdin. source: README
OSV-Scanner: Scan targets: Project dependencies, checked against the OSV database. source: README
sqlmap: Scan targets: Web application parameters: GET, POST, cookie, User-Agent and Referer values. source: Docs: Features
Promptfoo: Scan targets: LLM apps, through red teaming and vulnerability scanning. source: README
ZAP: Scan targets: Web applications. source: README
Nikto: Scan targets: Web servers: potentially dangerous files or programs, outdated server components. source: Docs: Overview & Description
How to install
go install github.com/ffuf/ffuf/v2@latestQuestions
Is ffuf open source?
Yes. ffuf is released under MIT, an OSI-approved license, as reported by the GitHub API on 2026-09-22.
Is ffuf maintained?
On 2026-09-22, the last commit to the default branch was on 2026-09-09, so the listed status is active. Rule: Last commit within 90 days of the fetch date.
How many GitHub stars does ffuf have?
16,703 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.
What language is ffuf written in?
The repository's primary language, as reported by the GitHub API, is Go.
How do I install ffuf?
The README gives this command: go install github.com/ffuf/ffuf/v2@latest
Sources
- GitHub REST API: repository, read
- GitHub REST API: commits, read
- GitHub REST API: latest release, read
- GitHub REST API: contributors, read
- README, read