codingo/nosqlmap

Automated NoSQL database enumeration and web application exploitation tool.

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 1 hour ago
Added to GitGenius on September 20th, 2026
Created on September 24th, 2013
Open Issues & Pull Requests: 1 (+0)
GitHub issues: Enabled
Number of forks: 628
Total Stargazers: 3,352 (+0)
Total Subscribers: 104 (+0)

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 0
New in 7 days: 0
Closed in 7 days: 0
Avg open age: N/A days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • no-issue-activity (8)
  • enhancement (1)
  • hacktoberfest (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

NoSQLMap is a penetration testing tool that automates injection attacks and exploitation of NoSQL databases and web applications.

The tool addresses security vulnerabilities in NoSQL deployments by identifying and exploiting injection flaws and default configuration weaknesses. It works through a menu-driven interface that guides users through building and executing attacks against target databases or web applications. The approach is modeled after sqlmap, applying similar automation concepts to the NoSQL attack surface rather than traditional SQL injection.

NoSQLMap is suited for security auditors and penetration testers assessing MongoDB and CouchDB deployments. It works best in environments where you have authorization to test NoSQL instances or web applications that use NoSQL backends. The tool is particularly valuable for discovering data exposure risks through injection vulnerabilities and for testing whether databases accept unauthenticated connections with default configurations. Future versions are planned to support Redis and Cassandra, though current focus remains on MongoDB and CouchDB.

Development activity shows consistent maintenance with Docker support added for easier deployment and setup automation provided through shell scripts for Debian and Red Hat systems. The project maintains active communication channels for user questions and suggestions, indicating ongoing engagement with its user base.