ImmuniWeb® On-Demand is a web application penetration testing platform that combines machine learning technology with manual security testing conducted by CREST-accredited penetration testers. The platform provides comprehensive web application security assessments that cover OWASP Top 10, OWASP Top 10 API, SANS Top 25, and PCI DSS 6.2.4 requirements. Testing includes both automated vulnerability scanning and manual penetration testing with business logic analysis. Key features include authenticated testing with multi-factor authentication and single sign-on support, REST/SOAP/GraphQL API security testing, and cloud-specific vulnerability assessment for applications hosted on AWS, Azure, and GCP. The platform can test both internal and external web applications using virtual appliance technology. The service offers multiple testing packages ranging from Express Pro (1 day manual testing) to Ultimate (10 days with threat-led penetration testing). All packages include unlimited patch verification assessments within 100 days of report delivery. Reports are generated in multiple formats (web, PDF, JSON, XML, CSV) and include MITRE ATT&CK matrix mapping, CVE/CWE compatibility, CVSS v4 scoring, and compliance sections for PCI DSS and GDPR. The platform provides zero false-positives guarantee and rapid delivery service level agreements. Integration capabilities include DevSecOps tools like Jira, GitHub, GitLab, Splunk, and web application firewall (WAF) virtual patching for F5, Imperva, Barracuda, Fortinet, and Qualys systems. The platform supports continuous integration/continuous deployment (CI/CD) workflows and provides 24/7 access to security analysts.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Automatically redirect users from www to non-www for a secure connection.
ConDroid performs concolic execution of Android apps to observe 'interesting' behavior in dynamic analysis.
A deliberately weak and insecure implementation of GraphQL for testing and practicing GraphQL security
A comprehensive application security platform that combines runtime protection, security testing, and monitoring capabilities across the entire application lifecycle.
A tool that safely installs packages with npm/yarn by auditing them as part of your install process.
A device security analysis platform that provides comprehensive vulnerability scanning, SBOM management, and supply chain security monitoring for connected devices and their components.
A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.
An integrated software supply chain platform that combines repository management, security scanning, and DevSecOps capabilities for managing and securing the entire software development lifecycle.
An ASPM platform that provides software supply chain security through risk assessment, prioritization, and protection mechanisms.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.