Curated list of the top security testing tools for assessing web and mobile application vulnerabilities.
Get targeted exposure with custom position pinning and highlighted placement.
Open‑source web application security scanner with automated crawling, active scanning, and extensive scripting support.
Comprehensive web security testing platform offering intercepting proxy, scanner, intruder, repeater, and extender APIs.
Automated web vulnerability scanner that detects SQLi, XSS, RCE, and provides detailed remediation guidance.
AI‑driven web application scanner with proof‑based vulnerability detection and CI/CD integration.
Cloud‑based scanner that continuously monitors web apps for OWASP Top 10 and custom vulnerabilities.
Enterprise‑grade dynamic and static analysis suite for web and mobile applications with compliance reporting.
SaaS platform delivering static, dynamic, and software composition analysis for web and mobile codebases.
Developer‑centric static application security testing (SAST) tool with deep code analysis and remediation suggestions.
Developer‑first security platform that scans open‑source dependencies and container images for known vulnerabilities.
Continuous inspection tool that combines code quality and security analysis for many programming languages.
Dynamic application security testing (DAST) solution with advanced crawling, authentication handling, and reporting.
Open‑source, high‑performance web vulnerability scanner written in Ruby, supporting multi‑threaded scans.
Classic command‑line web server scanner that checks for outdated software, misconfigurations, and dangerous files.
Python‑based web application vulnerability scanner that performs black‑box testing and generates detailed reports.
Dynamic scanner that integrates with InsightVM for continuous vulnerability management across web apps.
Network mapper that includes NSE scripts for web application fingerprinting and vulnerability discovery.
Automated mobile app pen‑testing suite for Android & iOS, supporting static, dynamic, and binary analysis.
Open‑source static analysis tool that identifies security weaknesses in Android APKs.
Static analysis platform focusing on Android security issues, with customizable rule sets.
Mobile app security testing platform offering automated static & dynamic analysis with risk scoring.
Real‑time mobile threat detection SDK that identifies malicious behavior on Android and iOS devices.
Comprehensive mobile app security testing suite covering static, dynamic, and binary analysis.
Collection of scripts, test cases, and tools aligned with OWASP’s MSTG for systematic mobile testing.
Security testing framework for Android that enables dynamic analysis, exploit development, and device probing.
Open‑source mobile automation tool; when combined with security plugins it can drive security‑focused UI tests.
Extension for Burp Suite that simplifies traffic interception and analysis for Android and iOS apps.
Not a tool per se, but a structured checklist that guides manual and automated mobile security testing.
Cloud‑based platform that performs static and dynamic analysis of Android/iOS apps with CI/CD integration.
Enterprise‑grade solution for continuous monitoring of mobile app security posture in production.
Static analysis engine tuned for mobile codebases (Java, Kotlin, Swift, Objective‑C).
Enterprise SAST tool that includes rule packs for Android and iOS platforms.
Semantic code analysis engine that can detect security flaws in web and mobile source code via GitHub Actions.
Software composition analysis tool that identifies vulnerable third‑party libraries in web and mobile projects.
JavaScript library scanner that flags known vulnerable client‑side components used in web applications.
Hosted version of Mobile Security Framework offering on‑demand static and dynamic scans without local setup.