LLMMap
API—OSS—FREE—DOCS2/5
LL5.0#26 of 29
—Web—Windows—MacoutLinux—Android—iOS
Ranked in AI Security Testing Tools ·Free plan
About
LLMMap is ranked #26 of 29 in AI security testing tools on Inferse. It runs on Linux. There is a free plan.
Compared on AI security testing tools
- Prompt injection tests
- Yesgithub.com
- Jailbreak tests
- Yesgithub.com
- Data leakage tests
- Yesgithub.com
- Deployment mode
- self_hostedgithub.com
Facts
- Purpose
- LLMMap tests LLM-integrated applications for prompt injection by discovering HTTP injection points, generating targeted prompts, and checking findings for reliability.github.com · 4 Oct 2026
- Prompt coverage
- It includes 227 prompt injection techniques across 18 attack families in four prompt packs.github.com · 4 Oct 2026
- Detection
- A Generator LLM creates goal-aware prompts and a Judge evaluates target responses; detector signals can include heuristics and optional semantic similarity.github.com · 4 Oct 2026
- Supported LLMs
- The documented backends are Ollama, OpenAI, Anthropic, and Google, with Ollama as the local default that needs no API key.github.com · 4 Oct 2026
- Request input
- Targets can be supplied as a URL or a Burp Suite request export, with an asterisk marking an injection location.github.com · 4 Oct 2026
- Burp Suite
- LLMMap reads Burp Suite request exports natively and lists proxy support for traffic inspection.github.com · 4 Oct 2026
- Injection locations
- It supports injection in query parameters, request bodies, headers, cookies, and paths.github.com · 4 Oct 2026
- Obfuscation
- Its listed obfuscation methods include base64, homoglyphs, leet speak, and language switching.github.com · 4 Oct 2026
- Reliability
- Candidate findings are re-tested using Wilson confidence intervals; the documented defaults are five retries and three confirmations.github.com · 4 Oct 2026
- Safety
- Safe mode is enabled by default and restricts scans to low-risk prompt families, while risky families such as tool abuse and system override are blocked.github.com · 4 Oct 2026
- Data handling
- Scan workspaces store request metadata, configuration, and timing; sensitive prompt text and response bodies stay in memory and are not written to disk by default.github.com · 4 Oct 2026
- Dry run
- Dry-run mode plans a scan and selects prompts without making network connections to the target.github.com · 4 Oct 2026
- Notable limits
- The architecture document says adaptive TAP and out-of-band detection modules are reserved for future versions and inactive in the v1.0.0 scan pipeline.github.com · 4 Oct 2026
- Intended users
- The project describes LLMMap as a security testing tool for authorized use and says to test only systems owned by the user or covered by explicit written authorization.github.com · 4 Oct 2026
Best LLMMap alternatives
See all 12Where it ranks on Inferse
Sources
- github.com/Hellsender01/LLMMap· checked 4 Oct 2026
- github.com/Hellsender01/LLMMap/blob/main/docs/ARCH· checked 4 Oct 2026
- github.com/Hellsender01/LLMMap/blob/main/docs/AUTH· checked 4 Oct 2026



