Application Security

Application security tools and solutions for securing web applications, mobile apps, and software throughout the development lifecycle.

Explore 534 curated cybersecurity tools, with 15,216 visitors searching for solutions

Caido Logo

A lightweight web security auditing toolkit that simplifies security tasks and enhances productivity.

0
Helm GPG (GnuPG) Plugin Logo

Helm plugin for cryptographically signing and verifying charts with GnuPG integration.

0
ZAP The Zed Attack Proxy Logo

ZAP is an open-source web application security scanner that helps identify vulnerabilities through automated scanning and manual testing capabilities.

0
Lockfile Linting Logo

Lint lockfiles for improved security and trust policies.

0
express-brute Logo

A brute-force protection middleware for express routes that rate-limits incoming requests.

0
secure-json-parse Logo

A tool to prevent prototype poisoning in JSON parsing.

0
drozer Logo

drozer is an open source Android security testing framework that identifies vulnerabilities in mobile apps and devices through Android Runtime and IPC endpoint interaction.

0
TBV (Trust but Verify) Logo

Package verification tool for npm with various verification and testing capabilities.

0
StaDynA Logo

StaDynA is a system supporting security app analysis in the presence of dynamic code update features.

0
MARA Framework Logo

MARA is a Mobile Application Reverse engineering and Analysis Framework with various features for testing mobile applications against OWASP mobile security threats.

0
Gitleaks Logo

Gitleaks is a SAST tool for detecting and preventing hardcoded secrets in git repos.

0
Joi Security Logo

A CLI tool that performs security assessments on Joi validator schemas by testing them against various attack vectors including XSS, SQL injection, RCE, and SSRF.

0
Wapiti Logo

Web-application vulnerability scanner with extensive coverage of security testing modules.

0
Paros Logo

A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.

0
Fuzzapi Logo

Fuzzapi is a Rails application with a user-friendly UI for API_Fuzzer gem and Docker setup.

0
Androwarn Logo

Androwarn performs static analysis of Android applications using Dalvik bytecode examination to detect and report potentially malicious behaviors.

0
Runtime Mobile Security (RMS) Logo

Runtime Mobile Security (RMS) is a powerful web interface powered by FRIDA for manipulating Android and iOS Apps at Runtime.

0
Joint Advanced Application Defect Assessment for Android Application (JAADAS) Logo

JAADAS is a powerful tool for static analysis of Android applications, providing features like API misuse analysis and inter-procedure dataflow analysis.

0
OWASP API Security Top 10 Logo

A community website for API security news, vulnerabilities, and best practices

1
Gamma Ray Logo

Gamma Ray is a software that helps developers to look for vulnerabilities on their Node.js applications with a pluggable infrastructure for integration with vulnerabilities databases.

0
Hakiri Toolbelt Logo

A command line tool that automates vulnerability scanning of Ruby gems and Rails stack components by identifying CVE vulnerabilities in detected technology versions.

0
Checkov Logo

Checkov is a static analysis tool that scans infrastructure as code and performs software composition analysis to detect security misconfigurations and vulnerabilities in cloud infrastructure and dependencies.

0
DVHMA Damn Vulnerable Hybrid Mobile App Logo

DVHMA is an intentionally vulnerable Android hybrid mobile app built with Apache Cordova for security testing and educational purposes.

0
PAPIMonitor Logo

Python tool for monitoring user-select APIs in Android apps using Frida.

0

Application Security Tools - FAQ

Common questions about Application Security tools including selection guides, pricing, and comparisons.

Application security tools and solutions for securing web applications, mobile apps, and software throughout the development lifecycle.

Have more questions? Browse our categories or search for specific tools.