Active Filters:
📂 Web Application Security
Clear all filters

  Web Application Security

71 tools found

Showing 1-28 of 71 tool(s) in the category "Web Application Security"
Page 1 of 3
PyCript
Web Application Security

PyCript

Burp extension to encrypt/decrypt traffic with custom logic in Python, Go, Node.js, etc.

Pentest Mapper
Web Application Security

Pentest Mapper

Burp extension to map API flows and link them to custom security test checklists.

InterceptSuite
Web Application Security

InterceptSuite

Intercepts and inspects TLS/SSL traffic across all protocols beyond HTTP/S.

Swego
Web Application Security

Swego

Go webserver with many features, simple like Python's SimpleHTTPServer.

CAIDO
Web Application Security

CAIDO

Modern, lightweight web security proxy with clean UI and modular design for web testing.

HackTools
Web Application Security

HackTools

Browser extension with payloads, cheatsheets, shells for web app penetration testing.

WP Recon
Web Application Security

WP Recon

Tool for vulnerability recognition and blackbox info gathering on WordPress sites.

ZAP Proxy
Web Application Security

ZAP Proxy

Open-source scanner to find web app vulnerabilities, useful for developers and pentesters.

HTTP Toolkit
Web Application Security

HTTP Toolkit

Open-source tool to intercept, inspect, and modify HTTP(S) traffic for testing and debugging.

Hetty
Web Application Security

Hetty

HTTP toolkit for security testing, open source alternative to Burp Suite Pro.

BeEF
Web Application Security

BeEF

BeEF exploits web browsers for client-side attacks and security assessments.

ZERO Threat
Web Application Security

ZERO Threat

AI-powered continuous pentest platform detecting 40,000+ vulnerabilities in real time.

WuppieFuzz
Web Application Security

WuppieFuzz

WuppieFuzz is a coverage-guided REST API fuzzer focused on usability, flaw explainability, and modularity.

Wapiti
Web Application Security

Wapiti

Wapiti performs black-box scans on web apps, injecting payloads to identify vulnerabilities.

snyk API
Web Application Security

snyk API

Discover and test API and web app security, prioritize risks, and find/fix vulnerabilities.

OSTE Meta Scanner
Web Application Security

OSTE Meta Scanner

DAST meta scanner combining Nikto, ZAP, Nuclei, SkipFish, and Wapiti to detect web vulnerabilities.

WPScan Online
Web Application Security

WPScan Online

Scanner tailored to detect and assess vulnerabilities in WordPress websites with precision.

proxify
Web Application Security

proxify

Multifunction proxy with filtering, traffic replay and upstream support for Burp integration.

Nikto
Web Application Security

Nikto

Web server scanner detecting dangerous files, outdated versions, and config vulnerabilities.

ImmuniWeb
Web Application Security

ImmuniWeb

Free app/API security, phishing detection, and dark web monitoring for awareness and safety.

GraphQL Security
Web Application Security

GraphQL Security

Quickly assesses GraphQL app security for vulnerabilities and misconfigurations.

Veracode Dynamic Analysis
Web Application Security

Veracode Dynamic Analysis

Dynamic scanner to detect risks in web apps and APIs for agile development teams.

Burp Suite Community
Web Application Security

Burp Suite Community

Free manual toolkit to start web application security testing.

Barrion
Web Application Security

Barrion

Automated scans to detect flaws in websites, web apps, and APIs no setup needed.

Indusface
Web Application Security

Indusface

PTaaS platform for testing apps/APIs, logic flaws, and continuous malware monitoring.

aikido
Web Application Security

aikido

DAST tool for monitoring apps/APIs to detect OWASP risks like XSS, SQLi, and CSRF.

HTTP Observatory
Web Application Security

HTTP Observatory

Scanner that checks websites for compliance with recommended security best practices.

cleanhttp
Web Application Security

cleanhttp

Library to detect and filter wildcard HTTP servers using signature-based rules.

GPT - RedTeam.Blue