ScanReview

Web Application Security Tools

Tools for testing web applications, APIs, proxies, templates, and scanner workflows.

Abstract external attack surface management visualization

Web Application Security Tools

Open-source web application security testing tools for DAST, API testing, and web app pentesting — intercept, scan, and secure modern web stacks.

Web proxy and application security testing dashboard

Web Proxies & Scanners

Intercept, inspect, and automate testing of HTTP/HTTPS traffic — the foundation of web app security testing.

Burp Suite

Industry-leading web proxy and scanner — intercept traffic, fuzz parameters, and automate vulnerability detection.

Download →

OWASP ZAP

Free open-source web app scanner — automated scanning, passive/active testing, API, and extensive plugin ecosystem.

GitHub →

mitmproxy

Interactive TLS-capable intercepting proxy — inspect, modify, replay, and script HTTP/HTTPS traffic flows.

GitHub →
Template-based web vulnerability scanning

Vulnerability Scanning

Template-driven and signature-based scanners for rapid detection of known vulnerabilities and misconfigurations.

Nuclei

Fast template-based vulnerability scanner — thousands of community templates for CVEs, misconfigs, and exposures.

GitHub →

Wafw00f

Web application firewall fingerprinting — identifies and detects 150+ WAF products protecting web applications.

GitHub →

XSpear

Advanced XSS vulnerability scanner with powerful analysis — static, pattern-based, and DOM-based detection.

GitHub →
API security testing and automated scanning

API Security Testing

Tools for discovering, enumerating, and testing REST, GraphQL, and other API endpoints for vulnerabilities.

Kiterunner

Contextual API content discovery — brute-forces API endpoints with route-aware wordlists and pattern matching.

GitHub →

Arjun

HTTP parameter discovery — finds hidden GET/POST parameters using a large default dictionary and heuristic detection.

GitHub →

Client-Side & JS Analysis

Extract endpoints, secrets, and attack surface from JavaScript files and client-side code.

LinkFinder

Discovers API endpoints and URLs buried in JavaScript files — essential for modern SPA and JS-heavy apps.

GitHub →

SecretFinder

Detects API keys, access tokens, JWTs, and sensitive data hidden in JavaScript files using regex patterns.

GitHub →

Authentication & Session

Test, crack, and manipulate JWT tokens, session cookies, and authentication mechanisms.

jwt_tool

Comprehensive JWT testing toolkit — scan, tamper, crack, and forge JSON Web Tokens with dozens of checks.

GitHub →

jwt-cracker

Simple HS256/HS384/HS512 JWT brute-force cracker — fast C-based implementation for weak HMAC secrets.

GitHub →

Flask-Unsign

Brute-force and decode Flask session cookies — sign, unsign, and crack signed sessions with wordlist support.

GitHub →

XSS & Injection Testing

Focused tools for detecting, validating, and exploiting cross-site scripting and injection vulnerabilities.

Dalfox

Powerful XSS scanner and automation utility — parameter mining, DOM parsing, and blind XSS pipeline support.

GitHub →

XSStrike

Advanced XSS detection suite — context analysis, intelligent payload generation, and WAF evasion built in.

GitHub →

Parameter & Input Discovery

Uncover hidden parameters, inputs, and attack vectors through fuzzing and mining techniques.

ParamSpider

Mines parameters from web archives and search results — discovers inputs for further fuzzing and testing.

GitHub →