Tplmap
Detects server-side template injection and code execution.
What it does
Tplmap tests inputs that flow into server-side templates for template injection — a flaw that can escalate to running code on your server — and confirms the impact across a range of template engines.
What data you get
Confirmation of any template-injection point, the engine affected, and how far the flaw reaches, up to code execution where present.
Why it matters to your site
Template injection is easy to introduce and devastating when present, since it can lead to full server compromise. This checks a specific, high-impact flaw that broad scanners rarely confirm.
More in this category
Other specialised tools
sqlmap
★ FeaturedThe definitive tool for detecting and confirming SQL injection.
XSStrike
Advanced detection and confirmation of cross-site scripting.
Dalfox
Fast, parameter-focused XSS scanner and verifier.