For una herramienta de pruebas de seguridad para GraphQL, the strongest matches are szski/shapeshifter (szski/shapeshifter is a GraphQL security testing tool, directly fitting), swisskyrepo/graphqlmap (GraphQLmap is a dedicated pentesting engine for GraphQL endpoints) and doyensec/inql (InQL is a Burp Suite extension specifically designed for). dolevf/graphql-cop is also worth a look. Each is ranked by relevance to your query, popularity and recent activity.
Herramientas y frameworks automatizados diseñados para identificar vulnerabilidades de seguridad y errores de configuración en endpoints de API GraphQL.
GraphQL security testing tool
szski/shapeshifter is a GraphQL security testing tool, directly fitting the search for automated vulnerability scanning, though the limited evidence suggests a narrower focus on injection detection rather than the full range of features listed.
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
GraphQLmap is a dedicated pentesting engine for GraphQL endpoints, supporting injection detection and other security tests, making it a direct fit for automated vulnerability scanning of GraphQL APIs.
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
InQL is a Burp Suite extension specifically designed for automated GraphQL security testing, including introspection detection, injection testing, and vulnerability scanning, which directly matches your need for a GraphQL security scanning tool—though it requires Burp Suite rather than being a standalone tool.
Security Auditor Utility for GraphQL APIs
graphql-cop is a security auditor utility specifically for GraphQL APIs, which directly matches your need for a scanning tool — though its exact feature set may be narrower than some full-featured alternatives.