ScanReview
Tools for testing web applications, APIs, proxies, templates, and scanner workflows.
Open-source web application security testing tools for DAST, API testing, and web app pentesting — intercept, scan, and secure modern web stacks.
Intercept, inspect, and automate testing of HTTP/HTTPS traffic — the foundation of web app security testing.
Industry-leading web proxy and scanner — intercept traffic, fuzz parameters, and automate vulnerability detection.
Download →Free open-source web app scanner — automated scanning, passive/active testing, API, and extensive plugin ecosystem.
GitHub →Interactive TLS-capable intercepting proxy — inspect, modify, replay, and script HTTP/HTTPS traffic flows.
GitHub →
Template-driven and signature-based scanners for rapid detection of known vulnerabilities and misconfigurations.
Fast template-based vulnerability scanner — thousands of community templates for CVEs, misconfigs, and exposures.
GitHub →Web application firewall fingerprinting — identifies and detects 150+ WAF products protecting web applications.
GitHub →Advanced XSS vulnerability scanner with powerful analysis — static, pattern-based, and DOM-based detection.
GitHub →
Tools for discovering, enumerating, and testing REST, GraphQL, and other API endpoints for vulnerabilities.
Extract endpoints, secrets, and attack surface from JavaScript files and client-side code.
Test, crack, and manipulate JWT tokens, session cookies, and authentication mechanisms.
Comprehensive JWT testing toolkit — scan, tamper, crack, and forge JSON Web Tokens with dozens of checks.
GitHub →Simple HS256/HS384/HS512 JWT brute-force cracker — fast C-based implementation for weak HMAC secrets.
GitHub →Brute-force and decode Flask session cookies — sign, unsign, and crack signed sessions with wordlist support.
GitHub →Focused tools for detecting, validating, and exploiting cross-site scripting and injection vulnerabilities.
Uncover hidden parameters, inputs, and attack vectors through fuzzing and mining techniques.
Mines parameters from web archives and search results — discovers inputs for further fuzzing and testing.
GitHub →