Tool · api-securityactive
BurpAPISecuritySuite
A Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
More tools
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- EvoMasterapi-securityState-of-the-art REST API fuzzer with a dedicated authorization SECURITY phase that flags access-control faults from two authenticated users.
- GraphQLerapi-securityDependency-aware GraphQL security tester that builds the query/mutation graph and runs two-profile cross-user IDOR/BOLA checks.
- Hadrianapi-securityPraetorian's headless OWASP-API authorization scanner covering BOLA, BFLA, OTP-brute/no-rate-limit ATO and mass-assignment with setup-attack-verify proof.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.