Skip to main content
Yanked

This release has been yanked by its maintainers, and will be ignored by installers, except when explicitly specified.
Consider using release 0.2.3 instead.
Reason given by maintainers: Fixed incorrect usage instructions in the README. The tool remains fully usable.

sorx

A lightweight CORS security analyzer for bug bounty hunters.

sorx is a CLI tool for analyzing CORS configurations and detecting potentially security-relevant misconfigurations with a focus on low noise and useful findings.

[!NOTE] sorx is currently under active development.

The project is not ready for use yet. The main executable/CLI is not available at this time, and functionality is still being implemented.

Features

  • CORS misconfiguration detection
  • Active origin fuzzing
  • Credential & origin reflection checks
  • Sensitive header analysis
  • HTTP method analysis
  • CORS combination checks
  • Configurable timeout, rate limit & threads
  • JSON output
  • Low-noise findings

Why sorx?

  • CLI-first — Designed to fit naturally into recon and bug bounty pipelines.
  • Free & open source — Free to use, inspect, modify, and contribute to.
  • Actively developed — Continuously improved with new checks, payloads, and features.
  • Low noise — Focuses on security-relevant CORS behavior instead of reporting every configuration.
  • Automation-friendly — Supports JSON output and configurable threads, rate limits, and timeouts.
  • Lightweight — Simple setup with minimal dependencies.
  • Built for hunters and testers — Designed around practical CORS testing workflows rather than generic HTTP scanning.

Installation

pip

Install:

pip install sorx

Update:

pip install -U sorx

pipx

Install:

pipx install sorx

Update:

pipx upgrade sorx

From Github

Install directly from GitHub:

pip install git+https://github.com/Pupsix/sorx.git

Or with pipx:

pipx install git+https://github.com/Pupsix/sorx.git

From Source

Clone the repository:

git clone https://github.com/Pupsix/sorx.git
cd sorx

Create a virtual environment:

python3 -m venv .venv
source .venv/bin/activate

Install in editable mode:

pip install -e .

The editable installation allows changes to the source code to be reflected immediately without reinstalling the package.

Recommended: Use pip or pipx for installation.
Installing from source is intended for development.

Usage

Basic scan:

sorx -u https://example.com

Enable active CORS fuzzing:

sorx -u https://example.com -a

Select testing mode:

sorx -u https://example.com -m quick
sorx -u https://example.com -m normal
sorx -u https://example.com -m deep

For all available options:

sorx --help

Responsible Use

sorx is intended for authorized security testing, including:

  • Bug bounty programs
  • Penetration testing
  • Security research
  • Applications you own

Only test targets where you have permission to perform security testing.

Do not use active fuzzing against unauthorized systems.

Status

sorx is currently under development.

The project focuses on useful findings rather than the number of checks. Some CORS configurations may be unusual without being vulnerabilities, so sorx attempts to prioritize security-relevant behavior and reduce unnecessary noise.

License

MIT License

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sorx-0.1.0.tar.gz (12.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sorx-0.1.0-py3-none-any.whl (14.1 kB view details)

Uploaded Python 3

File details

Details for the file sorx-0.1.0.tar.gz.

File metadata

  • Download URL: sorx-0.1.0.tar.gz
  • Upload date:
  • Size: 12.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for sorx-0.1.0.tar.gz
Algorithm Hash digest
SHA256 80244c38cc04be1dea8aed22be6c8e2aa229e64b453fc192cd79c2ba1a0132fa
MD5 993797e839589fe8a308a3072ef8a3e8
BLAKE2b-256 144a2fbf06308bb3067adfa7e0807ef05708fcdebeaa380a69e29be8e6db95a6

See more details on using hashes here.

File details

Details for the file sorx-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: sorx-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 14.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for sorx-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 7ad3ba6a3a131b78f3bac2ec44e276284e4f29fe093b0d520eb8e6284648b3a6
MD5 8324aabeb6f1f654e4e0c0cdd235b353
BLAKE2b-256 6275fff2413b2b1e548de237b73661d32a17ebfd74501a81010f8cc67fce2003

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.2

2 files

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page