Skip to content

Github · GitHub Repository Radar

swisskyrepo PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Stars

80,605

Popular Active

Forks

17,341

Watchers: 80,605

Language

Python

License: MIT License

Repository Radar Score

65 / 100

Growth

7d
+0
30d
+0
%
0.0%

Not enough metric snapshots yet to chart growth for this repository.

Score breakdown

  • popularity 92
  • growth 0
  • activity 90
  • freshness 100
  • community 90

Need help integrating this stack?

Our team builds with modern open-source stacks. Tell us what you are shipping.

Get a quote →

Payloads All The Things

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques!

You can also contribute with a 🍻 IRL, or using the sponsor button.

An alternative display version is available at PayloadsAllTheThingsWeb.

banner

📖 Documentation

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the other projects from the AllTheThings family :

You want more? Check the Books and YouTube channel selections.

🧑‍💻 Contributions

Be sure to read CONTRIBUTING.md

sponsors-list

Thanks again for your contribution! ❤️

🍻 Sponsors

This project is proudly sponsored by these companies.

Logo Description
sponsor-serpapi SerpApi is a real time API to access Google search results. It solves the issues of having to rent proxies, solving captchas, and JSON parsing.
sponsor-projectdiscovery ProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
sponsor-vaadata VAADATA - Ethical Hacking Services

Created: Oct 18, 2016

Last push: Aug 27, 2026

Default branch: master

Latest release: 4.2

Languages

Share of the codebase by language, based on repository metadata from the host.

  • Python 76.2%
  • ASP.NET 8.7%
  • XSLT 5.9%
  • Classic ASP 3.2%
  • PHP 3.1%
  • Ruby 1.2%
  • Jupyter Notebook 0.6%
  • CSS 0.5%
  • HTML 0.5%
  • JavaScript 0.2%
  • Shell 0.1%
  • Hack 0.0%

Repository Radar analysis

Deterministic insights derived from public metadata and our observations — not personal testing or reviews.

Why this repository is interesting

  • High absolute popularity (80,605 stars) signals broad adoption.
  • Maintained recently (last push 3 weeks ago).

Who should use it

  • Developers working primarily with Python
  • Security-minded engineers reviewing tooling options

Potential use cases

  • Reference or evaluate Python open-source approaches in this domain

Strengths

  • Recent repository activity
  • README present in our index
  • Declared license: MIT License
  • Substantial fork count (17,341) suggests reuse and contribution interest

Limitations / considerations

  • Insights are derived from public metadata and our observations — not a substitute for code review

What to watch

  • Re-check last push, issues, and releases on GitHub before production adoption

Strong signals: Strong community interest · Active maintenance

Source: GitHub (public metadata) + Repository Radar analysis. We do not claim ownership of third-party repositories.

Ready to ship something that compounds?

Share your roadmap. We’ll come back with scope options, timeline ranges, and who from Shriram IT Ventures should be in the room.

Popular with product teams