{"repo":"SoheilKhodayari/JAW","free":true,"listed":false,"github":"https://github.com/SoheilKhodayari/JAW","clone":"git clone https://github.com/SoheilKhodayari/JAW.git","description":"JAW: A Graph-based Security Analysis Framework for Client-side JavaScript","language":"JavaScript","stars":118,"topics":["csrf","javascript","neo4j","property-graph","vulnerability-detection","static-analysis","web-crawling","client-side"],"license":"AGPL-3.0","category":"dev-tools","readme_excerpt":"J A W Website Docs Setup Crawler Quick Start Docker (Example) JAW An open-source, prototype implementation of property graphs for JavaScript based on the esprima parser, and the EsTree SpiderMonkey Spec. JAW can be used for analyzing the client-side of web applications and JavaScript-based programs. This project is licensed under GNU AFFERO GENERAL PUBLIC LICENSE V3.0 . See here for more information. JAW has a Github pages website available at https://soheilkhodayari.github.io/JAW/ . Release Notes: - Sept 2025, JAW-v5: DOM gadget detection support via this fork. - Dec 2024, JAW-v4: JAW updated with open redirect detection queries. - Oct 2023, JAW-v3 (Sheriff): JAW updated to detect client-side request hijacking vulnerabilities. - July 2022, JAW-v2 (TheThing): JAW updated to its next major release with the ability to detect DOM Clobbering vulnerabilities. See JAW-V2 branch. - Dec 2020, JAW-v1 : first prototype version. See JAW-V1 branch. Content Overview of JAW 1. Test Inputs 2. Data Collection 3. HPG Construction 4. Analysis and Outputs Setup 1. Installation Quick Start 1. Running the Pipeline 2. Quick Example 3. Crawling and Data Collection - Playwright CLI with Foxhound - Puppeteer-based Crawler - Selenium-based Crawler 2. Graph Construction - HPG Construction CLI - HPG Import CLI 3. Security Analysis - Running Custom Graph traversals - Vulnerability Detection 4. Test Web Application Further Information 1. Detailed Documentation 2. Contribution and Code of Conduct 3. Academ","default_branch":null,"files":null,"tree":[],"storefront":"/r/SoheilKhodayari","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SoheilKhodayari/JAW/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}