Skip to content

A curated list of awesome GraphQL Security frameworks, libraries, software and resources

License

Notifications You must be signed in to change notification settings

glimow/awesome-graphql-security

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Awesome Graphql Security awesome

A curated list of awesome GraphQL Security frameworks, libraries, software and resources


Defensive Security

Continous Security Testing

  • Escape - GraphQL Security - Continuous GraphQL Security Testing for Developers. Find and fix GraphQL security flaws in the CI/CD.

Authentication & Authorization

  • GraphQL Shield - GraphQL Shield helps you create a permission layer for your application.

Offensive Security

Discovery

  • Voyager - Represent any GraphQL API as an interactive graph.
  • Graphinder - Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce.
  • Graphw00f - GraphQL Server Engine Fingerprinting utility

Exploitation

  • InQL - A Burp Extension for GraphQL Security Testing.
  • GraphQLMap - A scripting engine to interact with a GraphQL endpoint for pentesting purposes.
  • GraphQL.Security - One-click quick security scan of your GraphQL endpoints. Free, no login required.
  • GraphQL Path Enum - Tool that lists the different ways of reaching a given type in a GraphQL schema.

Vulnerable Applications

  • Damm Vulnerable GraphQL Application - Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

Resources

Vulnerabilities

Blogs

Contributing

Your contributions are always welcome! Please take a look at the contribution guidelines first.

We will keep some pull requests open if we are not sure whether those libraries are awesome, you could vote for them by adding 👍 to them.


If you have any question about this opinionated list, do not hesitate to contact us @escapetechHQ on Twitter or open an issue on GitHub.

About

A curated list of awesome GraphQL Security frameworks, libraries, software and resources

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published