
core
OPNsense GUI, API and systems backend

OPNsense GUI, API and systems backend

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

The DevSecOps toolset for REST APIs

Rust-powered HTTP Request Smuggling Scanner.

⚡️ Multiple target ZAP Scanning

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

MCP server for Slither static analysis of Solidity smart contracts

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Executable security regression testing for agentic applications and MCP-integrated systems.

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

Vulnerability Assessment Scanner with Report Generation