sqlmap is a popular feature-rich open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
Over time, sqlmap has become one of the main tools in the arsenal of professional cyber security consultant, software developers and SecDevOps that have implemented it for security assurance tests in the pipeline of software development. We believe that it has served its userbase well over the years and it will continue to do so.
sqlmap is the result of numerous hours of passionated work from a small team of computer security enthusiasts. If you appreciate our work and you want to see sqlmap kept being developed, please consider making a donation and sponsor our efforts. We have dedicated thousands of hours over the years to developing and maintaining it, as well as promptly acting on users' feedback, feature requests and bug reports.
Meet the team
Featured work
-
sqlmapproject/sqlmap
Automatic SQL injection and database takeover tool
Python 26,444
Select a tier
$1 a month
SelectSecurity enthusiast - are you a fan and want to support the team behind the development of sqlmap? This is the tier for you and we appreciate any support
$5 a month
SelectSecurity professional - you have used sqlmap during your penetration tests and it served you well
$10 a month
SelectRegular security professional - you regularly use sqlmap during your penetration tests and database reviews
$25 a month
SelectDevSecOps professional - you use sqlmap as part of continuous development to assess your applications
$50 a month
SelectSmall team of security professionals - your team uses sqlmap to offer cyber security consulting services to your customers
$100 a month
SelectTeam of DevSecOps - your team uses sqlmap as part of continuous development to assess your applications
$500 a month
SelectSecurity consulting - you represent a company and your team regularly use sqlmap during penetration tests and database reviews