Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Best overall for validated API findings: Detectify is the strongest choice when you can provide an OpenAPI or GraphQL schema and want exploit-response validation. Rapid7 InsightAppSec fits enterprise orchestration, Acunetix/Invicti covers REST, SOAP and GraphQL with detailed authentication controls, Intruder is practical for plan-supported CI pipelines, Probely is API-first, Pentest-Tools is report-oriented, and Burp Scanner is the best fit for teams combining automation with hands-on testing. No scanner wins every environment: the right choice depends on schema support, authenticated scope, deployment, finding validation and your pipeline’s reporting needs.
How to choose a website security scanning API
Evaluate each service against the same seven questions before buying or wiring it into CI:
- Control surface: Can the API create targets, configure scans, start and stop jobs, and retrieve vulnerabilities as JSON?
- Input formats: Does it accept OpenAPI, GraphQL, SOAP, Postman Collections, browser-discovered XHR calls, or only a URL?
- Authentication: Can it use OAuth 2.0, bearer tokens, JWT, API keys, Basic Auth, cookies, or dynamically refreshed credentials?
- Validation: Does it confirm a finding with an exploit request and response, or only report a signature match?
- Automation: Are rate limits, webhooks, ticketing, reports and regional endpoints documented for your pipeline?
- Deployment: Is the scanner hosted, self-managed, or available in both forms?
- Safety and cost: Can you limit methods, permissions, data-changing actions, scan frequency and plan usage?
| Product | Best fit | Schema and authentication coverage | Notable API or validation detail |
|---|---|---|---|
| Detectify | Validated REST and API testing | OpenAPI, GraphQL; OAuth 2.0, Basic Auth and API keys | Actual exploit requests and responses; API v2/v3 control surface |
| Rapid7 InsightAppSec | Enterprise orchestration | Targets and crawl/attack scope configured through its API | Create applications and targets, run scans, retrieve vulnerability JSON |
| Acunetix/Invicti | Mixed REST, SOAP and GraphQL estates | API key, bearer token, JWT, Basic Auth and OAuth 2.0 | REST API for targets, scans, vulnerabilities and reports |
| Intruder | Developer pipelines on eligible plans | API schemas and managed targets | REST API for targets, schemas, issues, scans and raw output; per-user rate limits |
| Probely | API-first teams and SPAs | OpenAPI/Swagger, Postman Collections and XHR discovery | Schema URL refresh and dynamic authentication tokens |
| Pentest-Tools | Focused website/API scanning and reports | API vulnerability scanner workflow | Publishes a sample report and a vendor benchmark |
| Burp Scanner | Automation plus manual web testing | Web application testing workflow | Found 29 of 39 DVWA issues in one February 2024 benchmark |
1. Detectify
Detectify has the broadest documented programmatic surface in this shortlist. API v2 and v3 expose assets, scans, vulnerabilities, scan profiles, DNS zones, teams and attack-surface data, so a pipeline can manage more than a one-off URL check. Its API Scanner consumes OpenAPI specifications or GraphQL schemas and supports OAuth 2.0, Basic Auth and API keys.
Recommended Free Tools
Why it stands out
The scanner sends exploit payloads and evaluates the API response to confirm whether a vulnerability is real. That validation approach is useful when false positives create expensive triage work. Detectify states a 99.7% true-positive rate for its web-application scanner; this is a 2026 vendor claim, not an independent measurement. Its product material also claims more than 330,000 command-injection payloads and more than 922 quintillion theoretical prompt-injection permutations; treat both figures as vendor claims rather than coverage guarantees.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Cost and caveats
Detectify lists API Scanning as a plan capability or add-on and advertises a starting price of €90 per month for API Scanning. Confirm the current currency, limits and included scope before purchase. Feed it a least-privilege test account and a schema that represents the endpoints you actually want tested.
2. Rapid7 InsightAppSec
InsightAppSec is a strong choice when security engineering needs a centrally managed workflow. Its API can create applications and targets, configure crawl and attack scope, start or stop scans, and retrieve vulnerability records. Rapid7 documents regional API base URLs and X-Api-Key authentication.
Pipeline pattern
A typical job creates or updates an application, attaches a target, posts a scan configuration, waits for completion, then queries vulnerabilities as JSON. Keep the application and target identifiers in your CI job’s state so retries do not create duplicates. Restrict crawl scope to the staging host and explicitly define out-of-scope paths.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
When to prefer it
Choose InsightAppSec when regional hosting, centralized reporting and repeatable scan orchestration matter more than importing a particular API schema. The published DVWA benchmark recorded 19 of 39 findings for InsightAppSec; that result is specific to that test environment and February 2024 methodology.
3. Acunetix/Invicti
Acunetix Premium exposes a REST API for targets, scans, vulnerabilities and reports. Its API scanner accepts REST, SOAP and GraphQL specifications, which is valuable for estates that contain older SOAP services alongside newer APIs. Supported authenticated methods include API keys, bearer tokens, JWT, Basic Auth and OAuth 2.0.
Permission scoping is essential
Acunetix documentation warns that production scans can change data and strongly recommends scanning APIs only in a non-production environment. Start with read-only methods, a disposable account and a staging database. Add write methods only after you have confirmed the scanner’s request sequence and rollback plan.
Benchmark context
Acunetix found 18 of 39 vulnerabilities in the February 2024 DVWA comparison published by Pentest-Tools. Use that number to understand one test’s coverage, not to claim a universal ranking.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
4. Intruder
Intruder’s REST API manages targets, API schemas, issues, scans and raw scanner output. It requires an access token and is rate-limited per user. The June 30, 2026 help documentation lists API availability on Cloud, Pro, Enterprise and Vanguard plans.
Integration fit
Intruder is practical when developers already use its hosted workflow and need scan creation plus issue retrieval in CI. Check that your subscription includes API access, then budget for rate-limit handling: queue jobs, back off on HTTP 429 responses and avoid launching a scan on every branch commit.
5. Probely
Probely is designed around APIs rather than treating them as an afterthought. For single-page applications it follows XHR calls; for standalone services it parses OpenAPI or Swagger schemas and Postman Collections. It can fetch a schema URL before each scan and use dynamically generated authentication tokens.
Good use cases
Use Probely when your specification is generated during deployment or when tokens expire between builds. Publishing the schema from the same commit as the service reduces drift. Verify the current hosted pricing and documentation address before procurement because those details can change.
Free tools Windows power users keep installed
One-click scans. No signup required.
6. Pentest-Tools Website/API Vulnerability Scanner
Pentest-Tools offers a focused website and API vulnerability scanner with a report-oriented workflow. Its API scanner has a sample report that helps teams judge whether the output contains the evidence, remediation context and export format their process requires.
Interpret its benchmark correctly
Pentest-Tools also publishes the 2024 web-application scanner benchmark used in this article. It is vendor-published comparative evidence, not a neutral certification. Read the methodology and environment details before using any ranking to select a product.
7. Burp Scanner
Burp Scanner is the best fit for teams that combine automated discovery with hands-on web testing. It is included in the Pentest-Tools DVWA comparison and reported 29 of 39 findings, the highest result among the listed tools in that test.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
What the number does and does not mean
The test ran against one DVWA environment in February 2024. Applications with different frameworks, authentication flows, business logic and rate limits can produce different results. Treat Burp’s score as directional evidence and validate it against your own representative staging application.
What the available benchmark actually shows
| Scanner | Findings in the February 2024 DVWA test | Interpretation |
|---|---|---|
| Burp Scanner | 29 of 39 | Highest result in this single environment |
| Rapid7 InsightAppSec | 19 of 39 | Directional result only |
| Acunetix | 18 of 39 | Directional result only |
The benchmark does not measure GraphQL coverage, authenticated API depth, false-positive rates across production-like systems, scan speed or total cost. Run a bake-off with the same endpoints, credentials, rate limits and acceptance criteria if those factors determine your decision.
A safe CI/CD integration pattern
There is no universal endpoint path or response schema across these vendors. Use each provider’s documented regional base URL, authentication header and resource paths, then normalize the returned records in your pipeline.
- Prepare a target: deploy a staging build, seed non-sensitive test data and create a least-privilege account.
- Describe the API: publish the OpenAPI, GraphQL, SOAP or Postman input supported by your scanner.
- Set scope: include only staging hosts and approved paths; exclude destructive operations until explicitly reviewed.
- Start asynchronously: create or reuse the application and target, launch the scan, and poll or receive a webhook.
- Retrieve JSON: fetch vulnerability records, preserve the scanner’s evidence and map severity to your policy.
- Gate deliberately: fail a build only on agreed severities and verified findings; archive raw output for audit and retest results.
Portable command-line template
export SCANNER_BASE_URL='https://your-regional-endpoint.example'
export SCANNER_API_KEY='replace-me'
export VULNERABILITIES_URL="$SCANNER_BASE_URL/your-documented-vulnerability-endpoint"
curl --fail-with-body -sS -H "X-Api-Key: $SCANNER_API_KEY" -H 'Accept: application/json' "$VULNERABILITIES_URL" -o vulnerabilities.json
jq '. | length' vulnerabilities.json
The URL path is intentionally supplied by your vendor’s documentation; Rapid7, Detectify, Acunetix/Invicti, Intruder, Probely and Burp do not share one compatible route. Do not copy a path from one product into another.
Portable Python normalizer
import json, os, requests
url = os.environ['VULNERABILITIES_URL']
headers = {'Accept': 'application/json'}
if os.getenv('SCANNER_API_KEY'):
headers['X-Api-Key'] = os.environ['SCANNER_API_KEY']
r = requests.get(url, headers=headers, timeout=90)
r.raise_for_status()
data = r.json()
items = data if isinstance(data, list) else data.get('vulnerabilities', data.get('issues', []))
for item in items:
print(json.dumps({
'id': item.get('id'),
'name': item.get('name') or item.get('title'),
'severity': item.get('severity'),
'url': item.get('url')
}, sort_keys=True))
Portable Node.js retrieval
const url = process.env.VULNERABILITIES_URL;
if (!url) throw new Error('Set VULNERABILITIES_URL to the provider-documented endpoint');
const headers = { Accept: 'application/json' };
if (process.env.SCANNER_API_KEY) headers['X-Api-Key'] = process.env.SCANNER_API_KEY;
const res = await fetch(url, { headers });
if (!res.ok) throw new Error(`${res.status} ${await res.text()}`);
const data = await res.json();
const items = Array.isArray(data) ? data : (data.vulnerabilities || data.issues || []);
console.log(JSON.stringify(items, null, 2));
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Authenticated scanning without creating damage
- Use a staging environment with resettable data and monitor outbound requests.
- Grant only the permissions needed to exercise the intended endpoints.
- Start with GET and safe read methods; review every POST, PUT, PATCH and DELETE before enabling it.
- Use short-lived OAuth, JWT or bearer credentials and rotate them after a run.
- Throttle scans to respect application limits and avoid triggering account lockouts or bot defenses.
- Record the schema commit, scanner profile, credential role and scope with every result.
Performance, reliability and cost decisions
Schema-driven scans usually reduce discovery ambiguity, while browser or XHR discovery can reveal routes missing from an outdated specification. Dynamic authentication prevents false unauthenticated results but adds token-service dependencies. Hosted scanners reduce maintenance; self-managed components may be preferable when traffic or findings cannot leave your network. Compare recurring plan limits, API availability, concurrent jobs, retention and report exports rather than comparing a headline price alone.
Or skip the browser setup
ScreenshotNeo is not a vulnerability scanner; it is the alternative to try first when your pipeline also needs deterministic website screenshots for evidence, visual regression or ticket attachments. It accepts a URL through one GET request, removes cookie banners, newsletter popups and chat widgets before capture, and bills only clean shots: bot checks, blank pages, timeouts, failed loads and cache hits are not billed. Its MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.
Using the API requires an access key. See the ScreenshotNeo API documentation for all options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The Free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 shots, and every feature is available on every plan. Create a free ScreenshotNeo account.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Troubleshooting common failures
The API returns 401 or 403
Check the regional base URL, authentication header or token audience. Confirm the account or plan has API access, especially for Intruder, and ensure the credential’s role can read vulnerabilities as well as start scans.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11A scan finishes with no endpoints
Validate the OpenAPI, GraphQL, SOAP or Postman input, confirm the schema URL is reachable from the scanner, and check that authentication was applied before discovery. For SPAs, compare the scanner’s discovered XHR routes with browser network logs.
Results are noisy or duplicated
Pin a scan profile, deduplicate by provider finding ID plus affected URL, and require exploit evidence where the product supports it. Avoid comparing severities without mapping each vendor’s taxonomy to your own.
Jobs time out or hit rate limits
Reduce scope, lower concurrency, poll at an increasing interval and honor HTTP 429 retry guidance. Separate discovery from attack phases when the product allows it, and schedule full scans outside peak traffic.
A production endpoint changes data
Stop the job, revoke the test credential and restore the affected fixture. Move scanning to staging, restrict methods and permissions, and document an approval gate for any non-read operation.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhich scanner should you choose?
- Choose Detectify for schema-driven API testing with documented exploit-response validation.
- Choose Rapid7 InsightAppSec for enterprise applications, regional API control and centralized orchestration.
- Choose Acunetix/Invicti when REST, SOAP, GraphQL and multiple authentication methods must coexist.
- Choose Intruder when its plan, token model and per-user rate limits fit an existing developer workflow.
- Choose Probely when API specifications, Postman Collections or dynamic tokens are central to testing.
- Choose Pentest-Tools when a focused scanner and report workflow are the priority.
- Choose Burp Scanner when automated coverage must be paired with manual web security testing.
Whichever product you select, validate it against your own authenticated staging APIs. The published benchmark is useful context, but schema quality, permission scope and evidence-backed triage determine whether a scanner produces actionable risk findings in your environment.
Frequently Asked Questions
Can the February 2024 DVWA scores predict coverage for my API?
No. They describe one deliberately vulnerable web application and do not measure GraphQL depth, business-logic flaws, authentication complexity or production traffic behavior.
Should I upload an OpenAPI schema once or on every build?
Refresh it on every build when the specification is generated from the deployed commit; otherwise route drift can create false confidence.
How should vulnerability JSON be stored?
Keep the raw provider response with scan metadata, then store a normalized record keyed by provider finding ID, affected endpoint and commit so retests can close or reopen the same issue.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

