Skip to main content

hackable

Hack yourself before they do.

One-command website security check for people who have never run a security tool. Point it at your app, and in about ten seconds it tells you, in plain English, how a hacker would break in and exactly how to stop them.

$ pip install hackable
$ hackable https://myapp.com

hackable scanning a deliberately vulnerable demo app

The problem

Millions of apps are being built with AI right now by people who have never heard of OWASP. The apps work. They also leak database keys, take SQL injection, and let anyone log in as anyone. The existing scanners (ZAP, Nuclei, Burp) are expert tools with expert UX. They might as well be in another language.

hackable is the Let's Encrypt of pentesting: free, one command, plain English.

What it checks

14 checks. Before probing, hackable crawls your app like a visitor would, collecting real links and forms, so injection tests hit your actual inputs instead of guessed parameter names.

Check What it finds
SQL injection Error-based probes plus boolean differential checks (safe, GET-only)
Exposed files Public /.env, /.git/, config backups, with content verification (no false alarms from SPA fallbacks)
XSS Your input reflected unescaped into the page
Open redirects Your site redirecting visitors to attacker domains
CORS Arbitrary origins trusted with credentials
Debug mode Stack traces leaking from error pages
Login rate limiting 10 rapid wrong passwords, checking for pushback
Security headers HSTS, CSP, X-Frame-Options, and friends
Cookie flags Session cookies missing Secure, HttpOnly, or SameSite
TLS Missing HTTPS, expired certs, ancient TLS versions
Version disclosure Server headers announcing exact versions
HTTP methods Risky methods like TRACE
robots.txt Hidden paths handed to attackers on a plate
security.txt No standard contact for researchers to report issues

Every finding comes with what this means (one sentence, no jargon) and how to fix it (one sentence, actionable). You get a 0-100 score and an A-F grade.

Output

Terminal report, machine-readable JSON (--json), SARIF 2.1.0 for GitHub code scanning (--sarif), and a self-contained shareable HTML report card (--html report.html).

hackable https://myapp.com --html report.html
hackable https://myapp.com --fail-under 70   # exit 1 in CI if score < 70
hackable https://myapp.com --only sqli,xss   # run a subset of checks

GitHub Action

Drop it into your workflow and every push gets scanned:

- uses: Shifu34/hackable@v1
  with:
    target: https://myapp.com
    fail-under: 70

Results upload to the Security tab automatically.

Safety

hackable only sends harmless probes: no destructive payloads, no data deletion, no login attempts with real credentials, ~50-150 requests with delays and an identifying User-Agent. It will ask for confirmation before scanning unless you pass --yes.

Only scan apps you own or have explicit permission to test. Scanning without permission may be illegal.

Roadmap

  • Authenticated scans (test behind a login)
  • JavaScript-rendered app support
  • Scheduled scans with diff alerts

License

MIT

Metadata

Release files for hackable 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hackable 1.0.0
File Size Uploaded
hackable-1.0.0.tar.gz 25.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hackable 1.0.0
File Interpreter ABI Platform
hackable-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 54.9 kB

Release files / hackable-1.0.0.tar.gz

Download URL hackable-1.0.0.tar.gz
Size 25.9 kB
Tags Source
SHA-256 checksum
How to use checksums
0c059f7fe3402d4e18fa342207764c1168a7504fbcb887f85ea549b0260c13d0
BLAKE2b-256 checksum
How to use checksums
c3137d7a18463adc4130c0d437d8fb85f27890493d22c37763c5c282aaed4de1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.10

Release files / hackable-1.0.0-py3-none-any.whl

Download URL hackable-1.0.0-py3-none-any.whl
Size 29.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2f239c23787ff42c33fe0c4e052fedf634f4d125e19feaff4f0c951a6134161a
BLAKE2b-256 checksum
How to use checksums
73cec1f0af37da9a85676a67e5ad4c63f6d0fb67c96f883ab8b295c4b2addf65
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.10

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page