{"repo":"omar2535/GraphQLer","free":true,"listed":false,"github":"https://github.com/omar2535/GraphQLer","clone":"git clone https://github.com/omar2535/GraphQLer.git","description":"🔍A cutting edge context aware GraphQL API fuzzing tool!","language":"Python","stars":169,"topics":["api-testing-framework","graphql","api","automated-testing","cybersecurity","pentesting","appsec","fuzzing","llm-fuzzing"],"license":"MIT","category":"security-tools","readme_excerpt":"The only dependency-aware GraphQL API testing tool GraphQLer is a cutting-edge tool designed to dynamically test GraphQL APIs with a focus on awareness. It offers a range of sophisticated features that streamline the testing process and ensure robust analysis of GraphQL APIs such as being able to automatically read a schema and run tests against an API using the schema. Furthermore, GraphQLer is aware of dependencies between objects queries and mutations which is then used to perform security tests against APIs. Key features - Request generation : Automatically generate valid queries and mutations based on the schema (supports fragments, unions, interfaces, and enums based on the latest GraphQL-spec) - Dependency awareness : Run queries and mutations based on their natural dependencies - Resource tracking : Keep track of any objects seen in the API for future use and reconnaisance - Error correction : Try and fix requests so that the GraphQL API accepts them - Vulnerability detection output : Every confirmed vulnerability writes a detections/ folder containing raw log.txt (full request/response chain) and summary.txt (chain steps + final payload + response) - IDOR detection : Automatically detect insecure direct object reference vulnerabilities using dual-profile chain replay - Statistics collection : Shows your results in a easy-to-read file - Ease of use : All you need is the endpoint and the authentication token if needed - Customizability : Change the configuration file t","default_branch":null,"files":null,"tree":[],"storefront":"/r/omar2535","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/omar2535/GraphQLer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}