danielmiessler/SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List...

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 39 minutes ago
Added to GitGenius on March 2nd, 2026
Created on February 19th, 2012
Open Issues & Pull Requests: 12 (+0)
Number of forks: 25,096
Total Stargazers: 73,037 (+0)
Total Subscribers: 1,991 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 32.9 hours
Mean response time: 272.2 days
90th percentile: 1291.7 days
Tracked items: 103

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Work labelled "ci/cd" is answered fastest, typically in under an hour, while "enhancement" waits about 33 hours. Only 10% of issues opened in the past year have been closed. Three people close 94% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 8
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 179 days
Stale 30+ days: 8
Stale 90+ days: 7

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • enhancement (42)
  • bug (25)
  • help wanted (19)
  • question (14)
  • wordlist (14)
  • ci/cd (10)
  • n/a (8)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

SecLists is a comprehensive collection of multiple types of lists designed specifically for security assessments and penetration testing. Maintained by Daniel Miessler, Jason Haddix, Ignacio Portal, and g0tmi1k, the repository serves as a centralized resource that enables security testers to access numerous list types in a single location. The collection includes usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many additional list categories. The primary goal is to allow a security tester to clone the repository onto a new testing environment and immediately have access to every type of list that may be needed during an assessment.

Installation options are flexible, including direct zip downloads, git cloning without commit history for faster setup, complete git cloning with full history, and pre-packaged installations available on Kali Linux and BlackArch distributions. The repository size is substantial enough that approximate cloning time is estimated at around eight minutes and forty-one seconds at 50 megabytes per second.

SecLists is classified across multiple security domains including security testing, penetration testing, wordlists, payloads, vulnerability assessment, ethical hacking, fuzzing, brute-force techniques, cybersecurity data, and enumeration.

The repository includes references to similar projects and complementary wordlist tools, acknowledging the broader ecosystem of security testing resources. A note in the documentation warns that downloading the repository may trigger false-positive alarms from antivirus or anti-malware software, recommending that filepaths be whitelisted. The project is licensed under the MIT license and actively seeks community support through GitHub sponsorship options for both the founder and current maintainers.