Home

Awesome

graphql-wordlist

The only graphql wordlists you'll ever need.

Built using more than 60k distinct GraphQL schemas, collected using Goctopus

Wordlists are available in ./wordlists directory. The complete wordlist (with every category) is ./wordlists/wordlist.csv.

Learn more about how we crafted the wordlist in our dedicated blog post: https://escape.tech/blog/graphql-security-wordlist

Categories

Words are counted by categories:

Statistics

The 20 most common words for each category:

overall

the overall number of encounters of the word

Complete wordlists:

WordCount
input3173119
id1873451
limit701265
where508808
offset495580
first488821
after446756
before420286
sort405066
last404374
search302205
data290373
filter288213
page265749
orderBy220898
email194209
keywords185536
name152913
type137326
ids133096

operationType

the word is the typename of an operation (QueryTypename, MutationTypename, SubscriptionTypename)

Complete wordlists:

WordCount
Query45421
Mutation37593
Subscription11541
RootQueryType1757
RootQuery1753
RootMutation1649
RootMutationType1597
RootSubscriptionType1068
query_root743
subscription_root727
query606
mutation595
Mutations260
mutation_root220
QueryRoot122
PlatformQuery110
PlatformService110
Queries99
MutationRoot88
RootSubscription76

operationField

the word is a field of an operation (a query, mutation, or subscription)

Complete wordlists:

WordCount
users17584
user16016
resetPassword12745
products11533
group9358
updateUser9356
analytics8968
product8929
login8654
me8267
pages7343
menu6922
changePassword6917
categories6910
appSettings6872
category6854
company6568
groups6480
article6405
currentUser6393

queryType

the word is the QueryTypename

Complete wordlists:

WordCount
Query45421
RootQueryType1757
RootQuery1753
query_root743
query606
QueryRoot122
PlatformQuery110
Queries99
Domain70
QueryV145
QueryType26
PublicQuery22
RootSchemaQuery21
Root20
QueryContainer16
Object12
AppQuery11
ROOTQUERY9
frontendQuery9
HeadquartersQuery9

queryField

the word is a query field

Complete wordlists:

WordCount
user15656
users15594
products11514
group9179
product8714
me7994
analytics7202
menu6914
categories6902
appSettings6867
category6806
company6540
article6397
currentUser6366
news5800
pages5572
sitemap5551
links5527
slider5414
portfolio5363

mutationType

the word is the MutationTypename

Complete wordlists:

WordCount
Mutation37593
RootMutation1649
RootMutationType1597
mutation595
Mutations260
mutation_root220
PlatformService110
MutationRoot88
DomainContentMutation65
MutationV145
PublicMutation19
MutationType16
AppMutation11
ROOTMUTATION9
RootSchemaMutation9
frontendMutation9
ConvergeMutation8
snappetRootMutation8
MutationEntry8
HeadquartersMutation8

mutationField

the word is a mutation field

Complete wordlists:

WordCount
resetPassword12635
updateUser9317
login8140
changePassword6881
createUser6380
deleteMessage5886
deleteUser5804
requestPasswordReset4643
deleteOrganization4439
inviteUser4307
register4163
acceptInvite4153
subscribe4108
deleteVideo4099
deleteService4097
deleteIntegration4078
unsubscribe3946
deleteWebhook3879
deleteSubscriber3867
joinChannel3833

subscriptionType

the word is the SubscriptionTypename

Complete wordlists:

WordCount
Subscription11541
RootSubscriptionType1068
subscription_root727
RootSubscription76
Subscriptions15
SubscriptionRoot14
subscription6
SubscriptionType6
subscriptions4
Root4
AppSubscription3
SubscriptionsRoot3
TypesSubscriptionType3
AllSubscriptions3
GraphqlSubscription3
DefaultAppSubscriptions2
DagitSubscription2
GraphSubscription2
SchoolSubscription2
TwinPlantSubscriptions2

subscriptionField

the word is a subscription field

Complete wordlists:

WordCount
issuableAssigneesUpdated2814
issueCrmContactsUpdated2594
issuableTitleUpdated2551
issuableLabelsUpdated2441
issuableDatesUpdated2271
mergeRequestReviewersUpdated2221
issuableDescriptionUpdated2160
mergeRequestMergeStatusUpdated2160
issuableMilestoneUpdated2112
mergeRequestApprovalStateUpdated2066
workItemNoteCreated1931
workItemNoteDeleted1931
workItemNoteUpdated1931
loggingLiveTrail1763
messageUpdated1620
userUpdated1594
notificationAdded1581
root1575
conversationUpdated1559
postAdded1546

argument

the word is an argument name

Complete wordlists:

WordCount
input3173101
id1872365
limit701205
where508808
offset495580
first488812
after446756
before420286
sort405042
last404374
data290310
filter288024
search285114
page252480
orderBy220850
email193603
keywords185272
name152616
type136942
ids133078

type

the word is a type name

Complete wordlists:

WordCount
Query45414
Mutation37593
Subscription11541
RootQueryType1757
RootQuery1753
RootMutation1649
RootMutationType1598
RootSubscriptionType1068
query_root743
subscription_root727
query606
mutation595
Mutations260
mutation_root220
QueryRoot122
PlatformQuery110
PlatformService110
Queries99
MutationRoot88
RootSubscription76

field

the word is a field name (operation or object field)

Complete wordlists:

WordCount
users35168
user32032
resetPassword25490
products23065
group18715
updateUser18712
analytics17936
product17858
login17307
me16534
pages14686
menu13844
changePassword13833
categories13820
appSettings13744
category13708
company13136
groups12959
article12810
currentUser12786