
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

⚡️ Multiple target ZAP Scanning

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated Security Testing For REST API's

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

The DevSecOps toolset for REST APIs

End to End testing of Web, API, Cloud, Events and Security

Rust-powered HTTP Request Smuggling Scanner.

Automated testing suite with live traffic record and replay

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Vulnerability Assessment Scanner with Report Generation

Burp Extension for collaboration in Faraday