Introducing G2.ai, the future of software buying.Try now
Intruder
Sponsored
Intruder
Visit Website
Product Avatar Image
SQLmap

By SQLmap

Unclaimed Profile

Claim your company’s G2 profile

Claiming this profile confirms that you work at SQLmap and allows you to manage how it appears on G2.

    Once approved, you can:

  • Update your company and product details

  • Boost your brand's visibility on G2, search and LLMs

  • Access insights on visitors and competitors

  • Respond to customer reviews

  • We’ll verify your work email before granting access.

Claim Now
4.3 out of 5 stars

How would you rate your experience with SQLmap?

Intruder
Sponsored
Intruder
Visit Website
It's been two months since this profile received a new review
Leave a Review

SQLmap Reviews & Product Details

Value at a Glance

Averages based on real user reviews.

Perceived Cost

$$$$$
Product Avatar Image

Have you used SQLmap before?

Answer a few questions to help the SQLmap community

SQLmap Reviews (38)

Reviews

SQLmap Reviews (38)

4.3
38 reviews

Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
SHASHIDHAR KUDARI .
S
Small-Business (50 or fewer emp.)
"Helps developers"
What do you like best about SQLmap?

Many of the developers don't do penetration testing while developing the API and this tool can help all of them including me Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

I think they are providing it only for SQL db, but it might be helpful if they do it for nosql dbs also Review collected by and hosted on G2.com.

Atul T.
AT
security evangelist
Small-Business (50 or fewer emp.)
"A single masterpiece for hunting and automating sql injection"
What do you like best about SQLmap?

Its automation in finding and dumping database. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

Sometimes we need to give more details about db Review collected by and hosted on G2.com.

Priyanshu K.
PK
Software Engineer
Small-Business (50 or fewer emp.)
"A must-have tool for Pentesters"
What do you like best about SQLmap?

SQLmap automates the process of finding SQL injections in web applications. It performs advanced queries and supports different types of injections; it also has WAF bypass inbuilt. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

In some cases, it fails to detect injections, such as custom injections, but nothing else to dislike. Review collected by and hosted on G2.com.

Udesh B.
UB
Assistant Engineer - Information Security
Small-Business (50 or fewer emp.)
"Sqlmap is an open-source tool. It's a really good tool for SQLi, simple and useful."
What do you like best about SQLmap?

It can automatically detect and use the SQL injection vulnerability database and the access server. It has a very powerful detection engine, has a penetration tester variety of characteristics, accesses to the underlying file system to extract the fingerprint database connection and execute commands that take away Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

Difficulty in Interfacing, Having a good user interface (GUI) will help relate better with users. Review collected by and hosted on G2.com.

Bawantha C.
BC
Penetration Tester
Mid-Market (51-1000 emp.)
"Useful tool if you are working in Cyber Security Industry"
What do you like best about SQLmap?

Easy to use and Very fast when considering other SQL injection tools , Has lot of new and valuable SQL injection methods that are not practical to test manually Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

Even though the application is pretty fast considering the other software's in the market sometimes it tend to miss out on some more complex attacks Review collected by and hosted on G2.com.

IS
Security Consultant
Mid-Market (51-1000 emp.)
"Amazing Database Vulnerability Scanning and a Take Over Tool"
What do you like best about SQLmap?

Its automated process of database vulnerability detection and takeover. SQLmap is not only used for direct database scanning, but also used against web applications to identify potential SQL vulnerabilities in programming and etc. Its uses include vulnerability scanning and assessment of security, analysis of web applications and, mainly, penetration testing and database takeover. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

It generates a good amount of false positives. We have to manually check whether a detected vulnerability exists and then verify it. Still considering its detailed output structure and ease of use this is not that much of a problem because if you are using it, then the chances are that you are already a security professional who is capable of manually verifying the detected vulnerability. Review collected by and hosted on G2.com.

Keshani B.
KB
Intern
Enterprise (> 1000 emp.)
"Best Automated SQL Injection Vulnerability Scanner"
What do you like best about SQLmap?

Its ability to thoroughly scan a web application to find SQL injection vulnerabilities and automatically exploit a detected vulnerability to take over the database. SQLmap is provided preinstalled in Kali Linux and is an essential tool to any professional security tester. When given an URL, it automatically executes a thorough SQL injection scan and if possible extract the entirety of database details and DB user details. These enumerated DB information include databases, roles, privileges, users, tables and their columns and can even get hash values of passwords. It even has the ability to bypass firewalls (WAF) employing tamper scripts. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

Nothing of significance. As with any other vulnerability scanner, SQLmap also gives false positives and the tester must manually check and confirm whether a detected vulnerability exists in the target. Review collected by and hosted on G2.com.

Isuru S.
IS
Intern
Enterprise (> 1000 emp.)
"Best Automated SQL Vulnerability Scanner"
What do you like best about SQLmap?

Everything about it. It is an amazing and a powerful automated engine for detecting SQL Injection vulnerabilities and, if possible, for database takeover. We can customize its commands to target a specific outcome. Since it is open-source., it is free of cost and has a massive online community of user who can guide you on any sort of problem that arises along the way. Due to its thorough testing of all possible DB vulnerabilities, any penetration tester can easily can conduct DB testing without much to worry about. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

One is that it does not have a graphical user interface. It may prove to be a little bit difficult, than it actually is, to some users because of this. Still, even with the command line interface, the learning curve is so small with all the help and tutorials available online. Another thing to dislike is its generation of false positive vulnerability findings. Even though this is true with any sort of vulnerability scanning software, still if the number of false positives can be limited to a minimum, SQLmap would be more impressive. In any case, the tester needs to double check the reported vulnerability by manually testing it. Review collected by and hosted on G2.com.

Medhavi W.
MW
Information Security Analyst
Enterprise (> 1000 emp.)
"Best tool for sql injection tests."
What do you like best about SQLmap?

SQL map support for different kind of sql injections such as os injections, command injections and many more. sql map based on the python and it comes free with the Kali or you can download the repository from the internet and able to use in a linux based environment. most of the vulnerable sql injection vulnerabilities can able to exploit using this tool and this is an essential tool for penetration testings. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

SQL map is a command line tool and does not have any graphical user interface we need to memorize all the commands and it is a tool really hard to use and need and advanced knowledge about this tool for use it. Review collected by and hosted on G2.com.

CZ
Assistant lecturer
Mid-Market (51-1000 emp.)
"Best tool for sql injection"
What do you like best about SQLmap?

SQLmap automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It has a powerful detection engine. numerous specialty highlights for an ultimate penetration tester and an expansive scope of changes enduring from database fingerprinting, over information bringing from the database to getting to the file system and executing commands on the OS by via out-of-band connections. Review collected by and hosted on G2.com.

What do you dislike about SQLmap?

There is nothing dislike anything about this if there is GUI for SQLmap could be more useful. Review collected by and hosted on G2.com.

Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

SQLmap Comparisons
Product Avatar Image
Metasploit
Compare Now
Product Avatar Image
Burp Suite
Compare Now
Product Avatar Image
Acunetix by Invicti
Compare Now
SQLmap Features
API / Integrations
Extensibility
Reporting and Analytics
Issue Tracking
Reconnaissance
Vulnerability Scan
Command-Line Tools
Manual Testing
Test Automation