Mayhem is a security platform that brings code, API and dynamic software bill of materials (SBOM) security into one dashboard. Its approach combines network-aware fuzzing, symbolic execution and triage to find vulnerabilities. For code, it generates tests autonomously and provides a reproduction and backtrace for each defect. Its API testing checks for OWASP Top 10 API weaknesses and supports stateful, agentless testing. Reachability analysis helps identify software components on the attack surface. Mayhem provides vendor-neutral SARIF reports, real-time notifications and integrations including GitHub, Jenkins, GitLab, Jira, Slack, CircleCI, Azure DevOps, Google Chat and Travis CI. Deployment options include managed SaaS, private-cloud installation and closed-network installation; its command-line tools support macOS, Linux and Windows. The Mayhem for API free plan allows up to 50 scans per month. Paid API plans cost 236.00 USD per month and include additional scans, enterprise features and personalized support; paid plans have a free 30-day trial.
Who it is for
Mayhem suits teams looking to test code and APIs for vulnerabilities and assess software components on the attack surface. Deployment options include managed SaaS, private cloud and closed networks.
What is good
- Provides a reproduction and backtrace for code defects.
- API testing checks for OWASP Top 10 API weaknesses.
- Offers managed SaaS, private-cloud and closed-network deployment.
- Integrates with CI and issue-tracking tools.
- Free API plan allows 50 scans monthly.
What to know first
- Free API plan is capped at 50 scans per month.
- Paid API plans cost 236.00 USD per month.
- Enterprise SSO and LDAP or Active Directory integration are enterprise options.
Verdict
Mayhem combines code testing, API testing and dynamic SBOM analysis, with a free API tier and a stated 30-day trial for paid plans. Check scan limits and deployment or authentication requirements against your team’s needs.
Mayhem plans and pricing
All plansCompared on fuzz testing software
- Input generation methods
- hybrid
- Target types
- Linux binaries; Windows PE binaries; TCP/UDP applications; REST APIs; gRPC APIs; containers; automotive vECUs
- Coverage guidance
- Yes
- Crash triage
- Yes
- Execution mode
- hybrid
- Supported languages
- C/C++; Python; Go; Rust; Java
- CI/CD support
- Yes

