Tool · dast/web-app-scanneractivecloud cost
AI Vuln Scanner
A security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Deploys real cloud resources in your own account — this can cost money. Tear it down after use.
More tools
- Custom AI Agent (Burp)dast/web-app-scannerA Burp Suite extension (formerly Burp AI Agent) that integrates AI into web security testing: connects to 11 AI providers (Ollama, Claude, Gemini, OpenAI-compatible), exposes up to 59 MCP tools for external AI clients to drive Burp, includes passive/active scanners covering 62 vulnerability classes, and offers privacy modes with host anonymization and AES-256-GCM credential storage.
- OWASP ZAP (Zed Attack Proxy)dast/web-app-scannerOpen-source web-application security scanner and intercepting proxy with a large add-on marketplace (active/passive scan rules, AJAX/client spider, auth helper, automation framework, GraphQL/SOAP, SARIF reporting).
- XSRFProbedast/web-app-scannerA Python CSRF audit toolkit that crawls a target web app and runs 25+ checks for anti-CSRF token weaknesses, referer/origin validation bypasses and SameSite cookie issues, generating exploitable PoC payloads and JSON reports. GPLv3, v3.0.0, actively maintained.
- XSSerdast/web-app-scannerXSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.
- ZAP Extensionsdast/web-app-scannerThe official add-on repository for OWASP ZAP (Zed Attack Proxy), the open-source dynamic application security testing (DAST) scanner. Contains the modular add-ons (in the addOns directory, built with Gradle) that extend ZAP's active/passive scanning, fuzzing, and web-app testing capabilities; tagged appsec, security, and dast.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.