
Top picks: Code Intelligence, ParamPamPam, Rexsser — plus 45 more compared.
Application SecurityEvaluating DOMdig alternatives comes down to matching Application Security capabilities to your environment, integrations, and budget rather than chasing feature parity. The options below are compared on what actually drives a switch: coverage, deployment fit, pricing, and real reviews from security teams. Independent and vendor-neutral: we never sell rankings.
DOMdig is a free Dynamic Application Security Testing tool. Security professionals most commonly compare it with Code Intelligence, ParamPamPam, Rexsser, Xss-Sql-Fuzz, and VulnSign Dynamic Application Security Testing. All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to DOMdig, including their key features and shared capabilities.
AI-automated fuzz testing platform for detecting software vulnerabilities.
ParamPamPam is an open-source tool that detects and exploits web application vulnerabilities using fuzzing, SQL injection, and XSS techniques.
A Burp Suite plugin that extracts keywords from HTTP responses using regex patterns and tests for reflected XSS vulnerabilities within the target scope.
A Burp Suite plugin for automatically adding XSS and SQL payload to fuzz
DAST tool for scanning web apps, microservices, and APIs for vulnerabilities
Black box fuzzer and DAST tool for testing application security
Cloud-based vulnerability assessment tool for web application security
Dynamic application security testing tool for runtime vulnerability detection
AI-automated fuzz testing platform for detecting software vulnerabilities.
ParamPamPam is an open-source tool that detects and exploits web application vulnerabilities using fuzzing, SQL injection, and XSS techniques.
A Burp Suite plugin that extracts keywords from HTTP responses using regex patterns and tests for reflected XSS vulnerabilities within the target scope.
A Burp Suite plugin for automatically adding XSS and SQL payload to fuzz
DAST tool for scanning web apps, microservices, and APIs for vulnerabilities
Black box fuzzer and DAST tool for testing application security
Cloud-based vulnerability assessment tool for web application security
Dynamic application security testing tool for runtime vulnerability detection
DAST tool that scans live web apps to detect vulnerabilities in real-time
Web app vulnerability scanner with continuous scanning and authenticated testing
DAST scanner for Single Page Applications using headless browser technology
DAST tool for detecting web app vulnerabilities like SQL injection and XSS
DAST tool for scanning web apps and APIs for OWASP Top 10 vulnerabilities
Automated web vulnerability scanner for SQLi, XSS, and other web app flaws
DAST scanner for web apps & APIs with automated vuln detection & remediation
AI-driven automated security testing using fuzzing and symbolic execution
A tool to find XSS vulnerabilities in web applications
ConDroid is a concolic execution framework for Android applications that automates dynamic analysis by driving execution to specific code locations without manual interaction.
w3af is an open source web application security scanner that identifies over 200 types of vulnerabilities including XSS, SQL injection, and OS commanding in web applications.
A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.
Web-application vulnerability scanner with extensive coverage of security testing modules.
A web security tool that scans for vulnerabilities and known attacks.
A Burp Suite extension that passively scans JavaScript files to discover endpoint links and potential attack surfaces in web applications.
A Burp Suite extension that automates XSS vulnerability detection and validation through custom payload generation and response analysis.
A fast and simple DOM based XSS vulnerability scanner
Femida is a Python automation tool that integrates with Burp Suite to detect blind XSS vulnerabilities in web applications through HTTP request analysis.
EvoMaster is an AI-driven tool that automatically generates system-level test cases for web APIs and enterprise applications using evolutionary algorithms and dynamic program analysis.
Managed web app security scanning service covering OWASP Top 10 vulnerabilities
AI-enhanced web app vulnerability scanner with zero false-positive SLA
DAST platform for API and web app security testing with business logic focus
AppSec platform with API discovery, CI/CD-native DAST, and risk oversight
DAST platform for web app & API vulnerability scanning with AI-enabled features
AI-powered automated penetration testing platform for web apps, APIs & GraphQL
Cloud-based DAST solution for web app & API security with AI-powered scanning
AI-powered AppSec platform for DAST, IAST, API security with auto-remediation
An enterprise-scale dynamic application security testing (DAST) platform that provides automated vulnerability scanning and security assessment for web applications.
DAST tool for automated web app and API vulnerability scanning and testing
Enterprise DAST solution for runtime app and API security testing
DAST scanner that identifies web app vulnerabilities and attack surfaces
AI-powered vulnerability scanner for web apps and APIs
API penetration testing tool for identifying business logic flaws
Web app pentesting platform for GDPR, HIPAA, PCI-DSS compliance monitoring
Detects sensitive data (PII, PHI, PCI) across application stacks
AI-driven DAST tool for automated vulnerability testing of web applications
AI-powered DAST tool for business logic security testing of web apps and APIs
GraphQL-native DAST tool for security testing GraphQL applications
Common questions security professionals ask when evaluating alternatives and competitors to DOMdig.
The most popular alternatives to DOMdig include Code Intelligence, ParamPamPam, Rexsser, Xss-Sql-Fuzz, and VulnSign Dynamic Application Security Testing. These Dynamic Application Security Testing tools offer similar capabilities and are frequently compared by security professionals evaluating their options.
There are 48 alternatives to DOMdig listed on CybersecTools, all within the Dynamic Application Security Testing category. Each alternative is matched based on shared capabilities, tags, and NIST CSF coverage areas.
DOMdig is a free Dynamic Application Security Testing tool. You can use it at no cost. Both free and commercial alternatives are available for comparison.
DOMdig is a Dynamic Application Security Testing tool within the broader Application Security category. It is used by security professionals for dynamic application security testing capabilities and can be compared against 48 similar tools.