Web Application Security
71 tools found
PyCript
Burp extension to encrypt/decrypt traffic with custom logic in Python, Go, Node.js, etc.
Pentest Mapper
Burp extension to map API flows and link them to custom security test checklists.
InterceptSuite
Intercepts and inspects TLS/SSL traffic across all protocols beyond HTTP/S.
Swego
Go webserver with many features, simple like Python's SimpleHTTPServer.
CAIDO
Modern, lightweight web security proxy with clean UI and modular design for web testing.
HackTools
Browser extension with payloads, cheatsheets, shells for web app penetration testing.
WP Recon
Tool for vulnerability recognition and blackbox info gathering on WordPress sites.
ZAP Proxy
Open-source scanner to find web app vulnerabilities, useful for developers and pentesters.
HTTP Toolkit
Open-source tool to intercept, inspect, and modify HTTP(S) traffic for testing and debugging.
ZERO Threat
AI-powered continuous pentest platform detecting 40,000+ vulnerabilities in real time.
WuppieFuzz
WuppieFuzz is a coverage-guided REST API fuzzer focused on usability, flaw explainability, and modularity.
Wapiti
Wapiti performs black-box scans on web apps, injecting payloads to identify vulnerabilities.
snyk API
Discover and test API and web app security, prioritize risks, and find/fix vulnerabilities.
OSTE Meta Scanner
DAST meta scanner combining Nikto, ZAP, Nuclei, SkipFish, and Wapiti to detect web vulnerabilities.
WPScan Online
Scanner tailored to detect and assess vulnerabilities in WordPress websites with precision.
proxify
Multifunction proxy with filtering, traffic replay and upstream support for Burp integration.
Nikto
Web server scanner detecting dangerous files, outdated versions, and config vulnerabilities.
ImmuniWeb
Free app/API security, phishing detection, and dark web monitoring for awareness and safety.
GraphQL Security
Quickly assesses GraphQL app security for vulnerabilities and misconfigurations.
Veracode Dynamic Analysis
Dynamic scanner to detect risks in web apps and APIs for agile development teams.
Barrion
Automated scans to detect flaws in websites, web apps, and APIs no setup needed.
Indusface
PTaaS platform for testing apps/APIs, logic flaws, and continuous malware monitoring.
aikido
DAST tool for monitoring apps/APIs to detect OWASP risks like XSS, SQLi, and CSRF.
HTTP Observatory
Scanner that checks websites for compliance with recommended security best practices.
cleanhttp
Library to detect and filter wildcard HTTP servers using signature-based rules.