StackHawk

Tester that boots your application locally and attacks it the way a bad actor would: it follows auth flows, replays requests with swapped identifiers, and covers the ten most common API risks catalogued by OWASP. The vendor also ships an agent skill that chains scan, fix and rescan inside one session.

Strengths

Limitations

Best for

Official site

View on Coeurdar