hackable
Hack yourself before they do.
One-command website security check for people who have never run a security tool. Point it at your app, and in about ten seconds it tells you, in plain English, how a hacker would break in and exactly how to stop them.
$ pip install hackable
$ hackable https://myapp.com
The problem
Millions of apps are being built with AI right now by people who have never heard of OWASP. The apps work. They also leak database keys, take SQL injection, and let anyone log in as anyone. The existing scanners (ZAP, Nuclei, Burp) are expert tools with expert UX. They might as well be in another language.
hackable is the Let's Encrypt of pentesting: free, one command, plain English.
What it checks
14 checks. Before probing, hackable crawls your app like a visitor would, collecting real links and forms, so injection tests hit your actual inputs instead of guessed parameter names.
| Check | What it finds |
|---|---|
| SQL injection | Error-based probes plus boolean differential checks (safe, GET-only) |
| Exposed files | Public /.env, /.git/, config backups, with content verification (no false alarms from SPA fallbacks) |
| XSS | Your input reflected unescaped into the page |
| Open redirects | Your site redirecting visitors to attacker domains |
| CORS | Arbitrary origins trusted with credentials |
| Debug mode | Stack traces leaking from error pages |
| Login rate limiting | 10 rapid wrong passwords, checking for pushback |
| Security headers | HSTS, CSP, X-Frame-Options, and friends |
| Cookie flags | Session cookies missing Secure, HttpOnly, or SameSite |
| TLS | Missing HTTPS, expired certs, ancient TLS versions |
| Version disclosure | Server headers announcing exact versions |
| HTTP methods | Risky methods like TRACE |
| robots.txt | Hidden paths handed to attackers on a plate |
| security.txt | No standard contact for researchers to report issues |
Every finding comes with what this means (one sentence, no jargon) and how to fix it (one sentence, actionable). You get a 0-100 score and an A-F grade.
Output
Terminal report, machine-readable JSON (--json), SARIF 2.1.0 for GitHub code
scanning (--sarif), and a self-contained shareable HTML report card
(--html report.html).
hackable https://myapp.com --html report.html
hackable https://myapp.com --fail-under 70 # exit 1 in CI if score < 70
hackable https://myapp.com --only sqli,xss # run a subset of checks
GitHub Action
Drop it into your workflow and every push gets scanned:
- uses: Shifu34/hackable@v1
with:
target: https://myapp.com
fail-under: 70
Results upload to the Security tab automatically.
Safety
hackable only sends harmless probes: no destructive payloads, no data deletion, no login attempts with real credentials, ~50-150 requests with delays and an identifying User-Agent. It will ask for confirmation before scanning unless you pass --yes.
Only scan apps you own or have explicit permission to test. Scanning without permission may be illegal.
Roadmap
- Authenticated scans (test behind a login)
- JavaScript-rendered app support
- Scheduled scans with diff alerts
License
MIT
Metadata
Release files for hackable 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hackable-1.0.0.tar.gz | 25.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hackable-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 54.9 kB
Release files / hackable-1.0.0.tar.gz
| Download URL | hackable-1.0.0.tar.gz |
|---|---|
| Size | 25.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0c059f7fe3402d4e18fa342207764c1168a7504fbcb887f85ea549b0260c13d0
|
|
BLAKE2b-256 checksum How to use checksums |
c3137d7a18463adc4130c0d437d8fb85f27890493d22c37763c5c282aaed4de1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.10
|
Release files / hackable-1.0.0-py3-none-any.whl
| Download URL | hackable-1.0.0-py3-none-any.whl |
|---|---|
| Size | 29.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2f239c23787ff42c33fe0c4e052fedf634f4d125e19feaff4f0c951a6134161a
|
|
BLAKE2b-256 checksum How to use checksums |
73cec1f0af37da9a85676a67e5ad4c63f6d0fb67c96f883ab8b295c4b2addf65
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.10
|