sqlmap: what the SQL injection tool actually does, and how to install it
GitHub describes it as Automatic SQL injection and database takeover tool. The repository metadata lists Python as its primary language. The metadata lists the NOASSERTION license. This article stays within the project description and details documented in the GitHub repository README.
At a glance
- What is it?
- sqlmap automates SQL injection detection and database takeover. This article covers what it is used for in cybersecurity, how the detection engine works, how to install it, and where it stops being the right tool.
- Who is it for?
- Adopt sqlmap when you have written authorisation to test a specific target and you need repeatable, evidence-producing SQL injection checks. Do not adopt it as a scanner you point at anything, and do not use it where a generic scanner is enough.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What sqlmap is used for in cybersecurity
sqlmap is a penetration testing tool. The README describes it as automating the process of detecting and exploiting SQL injection flaws and taking over database servers. That sentence contains the whole scope. It is not a general web scanner, and it is not a firewall or a code analyser. It takes a request you already know about, usually a URL with parameters or a saved HTTP request, and tries to prove that a parameter reaches a SQL query in a way an attacker can influence.
The audience is narrow and specific. It is written for penetration testers, for people studying for certifications that include web exploitation, and for defenders who want to reproduce a finding before they file it. The repository ships a user's manual, a FAQ, screenshots and a set of translations, which tells you the project expects readers who are learning the tool rather than reading its source.
The scope of the payoff is what separates sqlmap from a scanner that reports a possible injection. The README lists database fingerprinting, fetching data from the database, accessing the underlying file system, and executing commands on the operating system via out-of-band connections. Each of those is a step further into the target, and each one is a decision the tester has to make deliberately.
How the detection engine and the takeover path work
The repository layout shows the shape of the program. sqlmap.py is the command entry point, sqlmapapi.py exposes the same engine as a service, and sqlmapapi.yaml is the configuration that goes with it. The engine itself lives under lib/, the database-specific logic sits in plugins/, and tamper/ holds the scripts that rewrite payloads before they are sent.
That split matters when you are deciding whether to trust a result. Detection is not a single check. The tool sends candidate payloads through the parameter you gave it, observes how the response changes, and keeps going while the evidence holds. The tamper scripts sit between payload generation and the HTTP request, so a payload that a filter would block can be reshaped before it leaves the tool. This is why sqlmap finds things a fixed signature scanner does not, and also why the traffic it produces looks nothing like normal browsing.
The takeover path is a sequence, not a single command. Fingerprinting identifies the database management system. From there, the tool can fetch data, read or write files on the host, or reach the operating system through an out-of-band connection when the database allows it. The README does not promise that every step works on every target. It lists the capabilities as switches you can reach for, and the user's manual is where the conditions for each one are described.
Installing sqlmap and running a first check
The README gives cloning as the preferred route. It also offers tarball and zipball downloads from the repository. The clone command in the README uses a shallow clone into a directory named sqlmap-dev.
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-devAfter that, sqlmap works out of the box with Python 2.7 and 3.x on any platform, according to the README. There is no build step and no dependency installation step documented in the README. If you have seen a pip install sqlmap command elsewhere, note that the README does not describe one; it points at the repository, the tarball and the zipball.
Once you are inside the cloned directory, the README's usage section starts with the help output.
python sqlmap.py -hThat prints the basic options and switches. The README also documents a longer form for the complete list.
python sqlmap.py -hhThe README points to a sample run recording and to the user's manual for a description of every option along with examples. The README does not give a worked command for a live target, so the first real use is whatever the user's manual documents: a single URL with a parameter, run against a target you are authorised to test. Expect the tool to print its banner and report the parameter it is testing. The README does not document what the output looks like line by line; the sample run and the wiki screenshots are where that is shown.
Where sqlmap is the wrong tool
The clearest limit is in the name. sqlmap tests SQL injection. If your finding is a cross-site scripting flaw, an access control gap, or a misconfigured header, sqlmap has nothing to say about it, and running it will only tell you that no SQL injection was found in the parameters you gave it.
A second limit is that the tool needs a request to work on. It does not discover your application's attack surface by itself in the general case. The README lists a crawl capability among the switches, and the search data shows people asking what crawl does in sqlmap, but crawling is a mode you enable, not the default posture. If you do not know which parameter is worth testing, you are using the wrong stage of the process.
A third limit is noise. The engine sends many requests by design, and the level and risk switches change how many and how aggressive they are. On a production system with rate limits, an intrusion detection system, or a database that logs every malformed query, a default run can be disruptive. The README does not document a quiet mode or a rollback of anything the tool changes on the target, and the wiki is the place to check before pointing it at a live system rather than a staging copy.
Finally, there is a legal boundary. The README presents sqlmap as a penetration testing tool. Running it against a system you do not have written permission to test is not a technical question, and no switch in the tool changes that.
sqlmap against a general-purpose web scanner
The alternative most teams already have is a general web application scanner. The difference in approach is real and not a matter of quality. A general scanner walks a site, enumerates forms and parameters, and checks each one against a broad catalogue of vulnerability classes. It optimises for coverage and for a report a non-specialist can read.
sqlmap does the opposite. It takes one injection point and goes deep. It fingerprints the database, adapts payloads through the tamper scripts, and can continue past detection into data retrieval and file or command access. Where the general scanner answers "is there something here", sqlmap answers "what exactly is behind this parameter, and how far can it be pushed".
The practical consequence is workflow. A general scanner is a first pass across an unknown application. sqlmap is a second pass on a specific suspicion, or a reproduction step once a scanner has flagged something. Teams that treat the two as substitutes usually end up either with a long list of unverified findings or with a narrow test that missed everything outside SQL injection.
Maintenance, releases and the licence question
The repository is not archived, and the last push was on 2026-01-01. The most recent release is 1.10, tagged Tiarsus Helexina, dated the same day. Before that, 1.9 arrived on 2025-01-02 and 1.8 on 2024-01-03. That is roughly one release a year, which is a slow cadence for a tool whose target environment, database versions and web frameworks, changes faster than that. The practical upgrade cost is low because there is no build step: a fresh clone or a new tarball replaces the old directory. What you should re-read after an upgrade is the user's manual, since switches and behaviour are documented there rather than in a changelog you can diff.
The licence identifier in the repository metadata is NOASSERTION, which means the automated tooling could not classify it. The repository contains a LICENSE file at the top level, and the README links to it. If you plan to redistribute sqlmap, bundle it into a product, or use it in a commercial service, read that file and, if the terms are unclear to you, take advice. Nothing here is legal advice.
Editorial conclusion
Adopt sqlmap when you have written authorisation to test a specific target and you need repeatable, evidence-producing SQL injection checks. Do not adopt it as a scanner you point at anything, and do not use it where a generic scanner is enough. Before your first run, verify three things: that Python 2.7 or 3.x is available on the host, that the target is inside your engagement scope, and that you have read the level and risk switches in the user's manual, because those change how much traffic sqlmap sends.
Frequently asked questions
Is sqlmap legal?
The README presents sqlmap as a penetration testing tool. Whether running it is legal depends on whether you have permission to test the target, which is not something the tool or its documentation decides for you.
What databases are supported by sqlmap?
The README lists database fingerprinting among the switches and describes taking over database servers, but it does not enumerate the supported database management systems. The user's manual on the wiki is where the supported list is documented.
Is sqlmap allowed on OSCP?
The README does not mention OSCP or any certification exam policy. Exam rules come from the certification body, not from the tool's documentation, so check the current exam guide directly.
What is sqlmap used for?
The README describes it as automating the detection and exploitation of SQL injection flaws and the takeover of database servers, including fingerprinting, fetching data, accessing the file system and running operating system commands over out-of-band connections.
What is batch in sqlmap?
The README does not document a batch switch. It points to the user's manual for a description of all options and switches, and that is where the behaviour of a batch mode would be described.
What is level in sqlmap?
The README refers to a broad range of switches but does not describe a level option. The user's manual is the documented source for what each switch does, including any that affect how many payloads are tried.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/sqlmapproject-sqlmap)