Production-ready Bangladesh courier customer delivery history and delivery-risk checker with Vercel serverless APIs, privacy-first design, rate limiting, and secure provider integrations.
-
Updated
Aug 17, 2026 - TypeScript
Production-ready Bangladesh courier customer delivery history and delivery-risk checker with Vercel serverless APIs, privacy-first design, rate limiting, and secure provider integrations.
An intelligent web-proxy that monitors API requests of a web application and detects API security vulnerabilities automatically.
Simulate API attack patterns (BOLA, credential stuffing, shadow APIs, rate spikes) against your own dev/staging endpoints to verify your defenses.
Replace, load and replay Postman collections to Burp, Zap, etc.
API security assessment identifying logical vulnerabilities and business risks through safe, read-only testing using Postman for the Future Interns Cybersecurity Internship (Task 3).
A command-line tool for performance and security testing of Node.js APIs. It supports load testing, CSRF testing, session hijacking testing, JWT validation testing, XSS, SQL Injection, and other security vulnerabilities.
Amba2Pen is a Python-based tool designed to streamline the penetration testing process by automating various pentest tasks.
"FinVault Enterprise" — Fintech ecosystem with centralized authentication.
Vulnerable Express demo showing SQLi/XSS attacks before and after Argos runtime protection.
Track and measure penetration testing coverage in Burp Suite by recording and monitoring tested endpoints and parameters in real time.
AI-powered API security testing tool
Monitor your posture with this private, local application that sends alerts when you slouch.
Akto — independent third-party profile of a public API surface, by API Evangelist. Akto is a proactive API security platform that discovers, tests, and protects APIs and AI systems across an organization's infrastructure. Its open-source core (MIT, Java) delivers automated API discovery, API security posture management, and dynamic API security tes
A RESTful API brute-forcing tool in Go for ethical hacking practice. **Gobrute** is built for testing login passwords with multithreading, progress tracking, and customizable payloads, ideal for controlled environments like OWASP Juice Shop.
A-to-Z Bug Bounty Hunting Tools
Disclosure-safe IDOR/BOLA case study covering authorized access-control testing methodology, evidence handling, and remediation.
Real-time API threat detection and mitigation for FinTech systems
OWASP-Top-10-Security-Vulnerabilities-With-Node.js
BloodlessAPI - an offline API surface mapper. Imagine you are inside a penetration test and found a .json of an API - instead of digging it yourself, BloodlessAPI does it for you, and even suggests what's worth a look! Drop an OpenAPI/Swagger/Postman/HAR JSON and instantly get a clean endpoint map
To associate your repository with the api-security-testing topic, visit your repo's landing page and select "manage topics."