Tool · scanningactive
OWASP ZAP
Free OWASP DAST engine: spider, active scan, OpenAPI import and an access-control add-on for authorization testing.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsscanning
More tools
- Burp Suite ProfessionalscanningCommercial web vulnerability scanner and proxy, drivable via its REST API for automated active scanning.
- is-maliciousscanningMIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.