---
title: "sqlmap"
pageType: "tool-profile"
schemaVersion: "1.0"
snapshotId: "tv-20260915-f4c107995a2e"
generatedAt: "2026-09-15T07:02:20.000Z"
canonicalUrl: "https://toolvitals.com/tools/sqlmap/"
jsonUrl: "https://toolvitals.com/api/agent/tools/sqlmap"
indexable: true
---

# sqlmap

Automatic SQL injection and database takeover tool

## Decision context

- Status: active
- ToolVitals score: 91/100
- Health score: 89/100
- Shipping score: 93/100
- Score mode: verdict
- Data confidence: 90/100
- Source coverage: 95/100
- Last evidence check: 2026-09-14

## Classification

- Use case: Security Scanning (security-scanning)
- Category: Security & Compliance (security)
- Tool mode: Source-visible project
- Openness: OSI-approved OSS
- License: GPL-2.0
- Tags: open-source, database, detection, exploitation, pentesting, python, sql-injection, sqlmap, takeover, vulnerability-scanner, api-security, appsec, security-testing, security-testing-tool, sqlinjection, webapp-security

## Public repository signals

- Repository: [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap)
- Stars: 38442 (adoption context only)
- Forks: 6364
- Open issues: 31
- Last commit date: 2026-09-14
- Releases in 90 days: 0

## Source receipts

- [Official website](https://sqlmap.org/) — checked 2026-09-14
- [Source repository](https://github.com/sqlmapproject/sqlmap) — checked 2026-09-14

## Discovery status

- Search indexable: yes
- Reason: sufficient tool evidence

## Interpretation limits

- ToolVitals scores summarize bounded public maintenance, shipping, openness, and evidence signals. They are not user-review ratings.
- GitHub stars and related popularity metrics are adoption context, not quality evidence.
- Missing values mean not collected or not confidently established; they do not mean zero.
- Public signals do not prove security, uptime, support quality, customer satisfaction, or production suitability.
- Verify material decisions against the linked first-party sources and your own requirements.
