sqlmap
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
What sqlmap is
sqlmap is a penetration testing tool that automates detecting and exploiting SQL injection flaws. It can also take over database servers. Its switches include database fingerprinting and fetching data from the database. Other switches access the underlying file system. It can execute operating system commands through out-of-band connections. The tool runs from the command line as a Python script on Python 2.7 or 3.x on any platform. The README suggests obtaining it by cloning the Git repository. A user manual on the project wiki documents every option and switch.
Written from the project's README, read , and its documentation (see sources).
- Category
- Security testing
- License
- GPL-2.0-or-later (LICENSE grants GPL version 2 or later and adds the authors' interpretation of derived works; alternative commercial licenses are offered by the authors.)
- Language
- Python
- Changelog
- Releases on GitHub
Repository metrics
Status
activeLast commit within 90 days of the fetch date.Computed from the last commit date and the archive flag on the fetch date. See the status rules.
Alternatives
Listed security testing tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from sqlmap's, with its source. See also sqlmap alternatives.
garak: Scan targets: LLMs and dialog systems reached through generators. source: README
Bandit: Scan targets: Python code, for common security issues. source: README
OWASP Nettacker: Scan targets: IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP/HTTPS URLs. source: README
RESTler: Scan targets: Cloud services through their REST APIs. source: README
Atheris: Scan targets: Python code and native extensions written for CPython. source: README
Trivy: Scan targets: Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes. source: README
Nuclei: Scan targets: Target URLs and hosts, from a single target or a list file. source: README
Gitleaks: Scan targets: Secrets such as passwords, API keys and tokens in git repositories, files and stdin. source: README
Comparisons
How to install
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-devQuestions
Is sqlmap open source?
Yes. sqlmap is released under GPL-2.0-or-later, an OSI-approved license, as reported by the GitHub API on 2026-09-22. LICENSE grants GPL version 2 or later and adds the authors' interpretation of derived works; alternative commercial licenses are offered by the authors.
Is sqlmap maintained?
On 2026-09-22, the last commit to the default branch was on 2026-09-20, so the listed status is active. Rule: Last commit within 90 days of the fetch date.
How many GitHub stars does sqlmap have?
38,492 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.
What language is sqlmap written in?
The repository's primary language, as reported by the GitHub API, is Python.
How do I install sqlmap?
The README gives this command: git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
Sources
- GitHub REST API: repository, read
- GitHub REST API: commits, read
- GitHub REST API: latest release, read
- GitHub REST API: contributors, read
- LICENSE file, read
- README, read