Check your WAF before an attacker does
-
Updated
Jul 20, 2026 - Python
Check your WAF before an attacker does
The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.
Automated API security testing
Pentest Coverage Tracker is a Burp Suite extension that helps penetration testers monitor testing coverage in real time. It logs discovered endpoints and tracks whether their parameters are actually tested in Burp Suite. This helps highlight untested attack surfaces and provides clear visibility of coverage for security teams.
ScriptOcalypse 🏴☠️- Nothing here… just a lot of weird ideas with a chaotic mix of lemonade, boredom, and automation that somehow work.
Multi-layer API Security Analyzer built with FastAPI + ML anomaly detection.
Professional API security auditing tool that detects rate limiting vulnerabilities and misconfigurations in REST APIs
Lightweight CLI tool for scanning REST APIs for CORS issues, methods, and info leaks.
BloodlessAPI - an offline API surface mapper. Imagine you are inside a penetration test and found a .json of an API - instead of digging it yourself, BloodlessAPI does it for you, and even suggests what's worth a look! Drop an OpenAPI/Swagger/Postman/HAR JSON and instantly get a clean endpoint map
Simulate API attack patterns (BOLA, credential stuffing, shadow APIs, rate spikes) against your own dev/staging endpoints to verify your defenses.
An intelligent web-proxy that monitors API requests of a web application and detects API security vulnerabilities automatically.
Replace, load and replay Postman collections to Burp, Zap, etc.
Amba2Pen is a Python-based tool designed to streamline the penetration testing process by automating various pentest tasks.
AI-powered API security testing tool
Track and measure penetration testing coverage in Burp Suite by recording and monitoring tested endpoints and parameters in real time.
To associate your repository with the api-security-testing topic, visit your repo's landing page and select "manage topics."