awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
OWASP avatar

OWASP/OFFAT

0
View on GitHub↗
660 stars·89 forks·Python·MIT·7 viewsowasp.org/OFFAT↗

OFFAT

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

Features

  • REST API Security Tools - Autonomous assessment tool for identifying common API vulnerabilities.

Star history

Star history chart for owasp/offatStar history chart for owasp/offat

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to OFFAT

Similar open-source projects, ranked by how many features they share with OFFAT.
  • alufers/mitmproxy2swaggeralufers avatar

    alufers/mitmproxy2swagger

    9,530View on GitHub↗

    mitmproxy2swagger is a tool that transforms captured mitmproxy network traffic into structured OpenAPI schemas for reverse-engineering REST APIs. It functions as an OpenAPI schema converter and network traffic documentation utility, extracting API endpoints and data structures from captured network packets to create formal technical references. The tool enables the reconstruction of undocumented APIs by converting intercepted HTTP request and response patterns into specifications. It supports merging multiple traffic capture files into a single schema to incrementally expand an API map and ut

    HTMLmitmproxyopenapireverse-engineering
    View on GitHub↗9,530
  • api-security/apikitAPI-Security avatar

    API-Security/APIKit

    2,270View on GitHub↗

    APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

    Java
    View on GitHub↗2,270
  • apiclarity/apiclarityapiclarity avatar

    apiclarity/apiclarity

    572View on GitHub↗

    An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.

    Go
    View on GitHub↗572
  • akto-api-security/aktoakto-api-security avatar

    akto-api-security/akto

    1,486View on GitHub↗

    Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

    Java
    View on GitHub↗1,486
See all 24 alternatives to OFFAT→

Frequently asked questions

What does owasp/offat do?

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

What are the main features of owasp/offat?

The main features of owasp/offat are: REST API Security Tools.

What are some open-source alternatives to owasp/offat?

Open-source alternatives to owasp/offat include: alufers/mitmproxy2swagger — mitmproxy2swagger is a tool that transforms captured mitmproxy network traffic into structured OpenAPI schemas for… api-security/apikit — APIKit:Discovery, Scan and Audit APIs Toolkit All In One. apiclarity/apiclarity — An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and… assetnote/kiterunner — Contextual Content Discovery Tool. blst-security/cherrybomb — Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API… akto-api-security/akto — Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+…