On this page
Overview
sqlmap is a CLI for detecting and confirming SQL injection in web application inputs. Its use belongs only on systems you own or targets covered by explicit testing authorization.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Automate detection and DBMS-specific verification
sqlmap is a CLI that tests HTTP inputs with SQL injection techniques and database-management-system fingerprints. It can consume URLs, saved HTTP requests, and proxy-integrated traffic, then expose enumeration functions for supported DBMS families.
Best fit
Fits authorized assessments and reproducible confirmation
It is useful for systems an organization owns or penetration tests with an agreed scope and window, especially when manual checks need to become reproducible commands. Detailed help, dependency checks, and the tamper-script catalog can be inspected locally without contacting a target.
Before adoption
Control authorization, load, and collected data before testing
Never run it against a system without explicit authorization. Automated testing may generate many requests or perform data operations, so agree on target URLs, parameters, test intensity, stop conditions, logs, and handling of collected data with the owner. The fixed LICENSE offers the source under GPLv2 or later with clarifications and a special exception, and also points embedders to separate proprietary licensing.
Official sources
- [1]sqlmap README at commit 1d9965d(2026-10-04)
- [2]sqlmap usage wiki(2026-10-04)
- [3]sqlmap FAQ(2026-10-04)
- [4]sqlmap GPLv2 license at commit 1d9965d(2026-10-04)
- [5]sqlmap GitHub repository metadata(2026-10-04)
Supplemental curator note
sqlmap serves assessors who need reproducible SQL injection checks for explicitly authorized applications. Begin with offline help and the tamper catalog, then agree on scope, intensity, stop conditions, and data handling with the system owner before contacting any target.
Try it in 3 steps
- 1
Check out the fixed commit in a temporary directory
Requires Git, Python 3, and network access. Clone the official repository into an isolated temporary directory and detach at the reviewed commit. This step does not contact a test target.
sqlmap_demo_dir=$(mktemp -d "${TMPDIR:-/tmp}/sqlmap-demo.XXXXXX") && cd "$sqlmap_demo_dir" && git clone --filter=blob:none https://github.com/sqlmapproject/sqlmap.git . && git checkout --detach 1d9965d0033d7a0e9e8bfd9cb066a5e4cb55b590 - 2
Inspect the version and local dependencies
From the same directory, print the CLI version and optional dependency status. No URL or saved request is supplied, so no assessment traffic is generated.
python3 sqlmap.py --version && python3 sqlmap.py --dependencies - 3
List the bundled tamper scripts
Inspect local transformation script names and descriptions. This inventories capabilities without scanning any external system.
python3 sqlmap.py --list-tampers
Growth
Growth trends · Last 30 days
38,604 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 27
- Open PRs
- 7
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- sql-injection
- detection
- exploitation
- python
- database
- pentesting
- api-security
- appsec
- security-testing
- security-testing-tool
- sqlinjection
- webapp-security
- Stars
- 38,604
- Forks
- 6,391
- Watchers
- 1,110
- Open issues
- 26
- Contributors
- 139
- Owner type
- Organization
- Primary language
- Python
- License
- Not determined
- Repository last updated
- Sep 28, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- mitmproxy45,257 Stars
2 shared tag(s) · 1 shared category(s) · Same language
inspect HTTP, HTTP/2, WebSocket, and TLS traffic interactively and transform flows with scripts
Python - JumpServer31,708 Stars
2 shared tag(s) · 1 shared category(s) · Same language
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Checkov9,053 Stars
2 shared tag(s) · 1 shared category(s) · Same language
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Python - kube-hunter5,087 Stars
2 shared tag(s) · 1 shared category(s) · Same language
probe Kubernetes clusters from outside or inside to expose reachable services and known security weaknesses
Python - Semgrep16,867 Stars
2 shared tag(s) · 1 shared category(s)
Find bugs and policy violations across languages with code-like patterns
C - Redash28,833 Stars
2 shared tag(s) · Same language
query multiple data sources and turn results into visualizations, dashboards, sharing, and alerts
Python
Report incorrect information
Tell us if any listing information is incorrect or outdated.