
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

⚡️ Multiple target ZAP Scanning

Automated testing suite with live traffic record and replay

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Stage two containers

Automated Security Testing For REST API's

Rust-powered HTTP Request Smuggling Scanner.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Server scanning component of purpleteam

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

TLS checking component of purpleteam

The DevSecOps toolset for REST APIs

Application scanning component of purpleteam

End to End testing of Web, API, Cloud, Events and Security

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…