
sqlmap
Open-source tool that automates detection and exploitation of SQL injection flaws and related database takeover techniques for authorised testing.
0 upvotes · 0 downvotes
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- WindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 30 September 2026
What it is
sqlmap is an open-source penetration testing tool that automates detection and exploitation of SQL injection flaws and related database takeover techniques. It is maintained by the sqlmap project, distributed from sqlmap.org and GitHub, and supports a wide range of database back ends with multiple injection techniques.
What it helps with
- Detecting SQL injection issues using boolean-based blind, time-based blind, error-based, UNION query and stacked-query techniques.
- Fingerprinting database back ends and working across many relational and some cloud data platforms described on the project site.
- Enumerating databases, tables and columns and extracting data where authorised testing permits.
- Demonstrating impact through file-system access or operating-system command execution when the back end and configuration allow it.
- Supporting authorised assessments with tamper scripts, proxies and other switches documented in the project wiki.
- Embedding the engine under a commercial licence when a vendor needs to ship sqlmap technology inside a proprietary product.
Who it's for
Web application penetration testers, AppSec engineers and students practising SQL injection testing on applications and labs they are authorised to assess.
Worth knowing
Use sqlmap only against targets you are authorised to test. Unauthorised use against third-party systems is illegal. The community edition is GPLv2; organisations that embed sqlmap in proprietary products can enquire about the commercial licence described on sqlmap.org. The project’s public brand imagery is the tarsier used on sqlmap.org. Attribution: feature and licensing summary from sqlmap.org and the GitHub README/wiki.