Graphql-Threat-Matrix – GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
Discription

# [![](https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284)]()

## Why graphql-threat-matrix?

[graphql-threat-matrix]( “graphql-threat-matrix” ) was built for bug bounty hunters, security researchers and [hackers]( “hackers” ) to assist with uncovering [vulnerabilities]( “vulnerabilities” ) across multiple GraphQL implementations.

The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations.

**Legend**

? – Enabled by Default

?? – Disabled by Default

? – No Support

Implementation | Validations | Field Suggestions | Query Depth limit | Query Cost Analysis | Automatic Persisted Queries | Introspection | Debug Mode | Batch Requests
—|—|—|—|—|—|—|—|—
[wp-graphql]( “wp-graphql” ) | [38]( “38” ) |

?

|

??

|

?

|

?

|

??

|

??

|

?

[graphql-php]( “graphql-php” ) | [37]( “37” ) |

?

|

??

|

??

|

?

|

?

|

??

|

??

[Apollo]( “Apollo” ) | [34]( “34” ) |

?

|

??

|

??

|

?

|

?

|

?

|

?

[graphql-yoga]( “graphql-yoga” ) | [34]( “34” ) |

?

|

??

|

?

|

?

|

??

|

??

|

??

[graphene]( “graphene” ) | [34]( “34” ) |

?

|

?

|

?

|

?

|

?

|

?

|

??

[Ariadne]( “Ariadne” ) | [34]( “34” ) |

?

|

??

|

??

|

?

|

?

|

??

|

?

[Strawberry]( “Strawberry” ) | [34]( “34” ) |

?

|

??

|

?

|

?

|

?

|

?

|

?

[graphql-ruby]( “graphql-ruby” ) | [28]( “28” ) |

?

|

?

|

??

|

??

|

?

|

?

|

?

[Sangria]( “Sangria” ) | [27]( “27” ) |

?

|

??

|

??

|

?

|

?

|

?

|

??

[Tartiflette]( “Tartiflette” ) | [26]( “26” ) |

?

|

?

|

?

|

?

|

?

|

?

|

?

[graphql-java]( “graphql-java” ) | [26]( “26” ) |

?

|

??

|

??

|

?

|

?

|

?

|

??

[gqlgen]( “gqlgen” ) | [25]( “25” ) |

?

|

?

|

??

|

??

|

?

|

??

|

??

[Dgraph]( “Dgraph” ) | [25]( “25” ) |

?

|

?

|

?

|

??

|

?

|

?

|

?

[graphql-go]( “graphql-go” ) | [24]( “24” ) |

?

|

?

|

?

|

?

|

?

|

??

|

?

[juniper]( “juniper” ) | [24]( “24” ) |

?

|

?

|

?

|

?

|

?

|

?

|

??

[Diana.jl]( “Diana.jl” ) | [10]( “10” ) |

?

|

?

|

?

|

?

|

?

|

?

|

?

[gql-dart/gql]( “gql-dart/gql” ) | [9]( “9” ) |

?

|

?

|

?

|

?

|

?

|

?

|

?

[Agoo]( “Agoo” ) | [0]( “0” ) |

?

|

?

|

?

|

?

|

?

|

??

|

?

## Want to provide a submission (or correction)?

Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details.

## Contributors & Maintainers

* [Nick Aleks]( “Nick Aleks” )
* [Dolev Farhi]( “Dolev Farhi” )

**[Download Graphql-Threat-Matrix]( “Download Graphql-Threat-Matrix” )**Read More

Back to Main

Subscribe for the latest news: