awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
flipkart-incubator avatar

flipkart-incubator/Astra

0
View on GitHub↗
2,639 stars·411 forks·Python·apache-2.0·6 views

Astra

Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles.

The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports.

The system supports the import of collection files to map endpoints and execute targeted security test suites. Its capabilities include automated vulnerability detection and mapping, as well as integration into DevSecOps pipelines.

Features

  • API Security Testing - Provides a specialized system for testing REST API endpoints for security vulnerabilities and flaws.
  • API Security Scanning Management - Provides a graphical interface for triggering and monitoring security scanning workflows.
  • Automated Vulnerability Detection - Automatically identifies common security weaknesses in web services to reduce manual testing effort.
  • Scanners - Implements an automated scanner to detect security flaws in REST API endpoints using imported collections.
  • Security Vulnerability Scanning - Analyzes REST API endpoints and collection files to detect common security vulnerabilities.
  • Vulnerability Management Interfaces - Offers a graphical interface for managing security scanning processes and vulnerability reports.
  • API Collection Runners - Executes targeted security test suites by importing API definition collection files to map endpoints.
  • DevSecOps and Automation - Integrates automated security testing into the software delivery cycle for early risk detection.
  • REST API Frontends - Ships a browser-based management interface that communicates with the backend via REST API endpoints.
  • Scan Process Monitoring - Provides a graphical interface for monitoring the progress of security scanning workflows.
  • API Vulnerability Categorization - Provides automated mapping of scan results against security patterns to categorize and prioritize API weaknesses.
  • General Web Scanners - Automated security scanner for web applications and APIs.
  • Penetration Testing - Automated security testing platform for REST APIs.
  • REST API Security Tools - Automated security testing framework for REST APIs.
  • Web Exploitation - Automated security testing for REST APIs.

Star history

Star history chart for flipkart-incubator/astraStar history chart for flipkart-incubator/astra

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Astra

Similar open-source projects, ranked by how many features they share with Astra.
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • r0oth3x49/ghaurir0oth3x49 avatar

    r0oth3x49/ghauri

    4,032View on GitHub↗

    Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable databases. It functions as a database exfiltration framework that identifies security flaws and retrieves system banners, hostnames, and database schemas. The tool identifies boolean, error, time-based, and stacked query vulnerabilities across multiple input vectors, including HTTP headers, cookies, JSON, SOAP, and XML. It provides capabilities for automated database exfiltration and the processing of bulk target lists to identify flaws across multiple environments. The syst

    Python
    View on GitHub↗4,032
  • dstotijn/hettydstotijn avatar

    dstotijn/hetty

    11,485View on GitHub↗

    Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit

    Go
    View on GitHub↗11,485
  • imperva/automatic-api-attack-toolimperva avatar

    imperva/automatic-api-attack-tool

    495View on GitHub↗

    Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

    Java
    View on GitHub↗495
See all 30 alternatives to Astra→

Frequently asked questions

What does flipkart-incubator/astra do?

Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles.

What are the main features of flipkart-incubator/astra?

The main features of flipkart-incubator/astra are: API Security Testing, API Security Scanning Management, Automated Vulnerability Detection, Scanners, Security Vulnerability Scanning, Vulnerability Management Interfaces, API Collection Runners, DevSecOps and Automation.

What are some open-source alternatives to flipkart-incubator/astra?

Open-source alternatives to flipkart-incubator/astra include: andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… r0oth3x49/ghauri — Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable… dstotijn/hetty — Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic… imperva/automatic-api-attack-tool — Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are… microsoft/restler-fuzzer — RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs… tennc/webshell — This is a webshell open source project.