Most pentesting tools are built for enterprise teams, heavy setup and noisy results. BattleTester is built for small sites and vibe coded apps that need real security coverage without the complexity. Easy to configure, no infrastructure, no steep learning curve API focused, targets how modern apps actually work Context-aware AI works on specific datasets, not just bashing against your site Less noise, clean, actionable reports
No reviews yetBe the first to leave a review for BattleTester
Maker
📌
Hey there :)
I'm the solo dev behind BattleTester. Been building this for the past year in my free time, and it's finally at a point where I feel good putting it out there.
Honestly the whole thing started because I kept seeing vibe coded apps go live with really basic security holes, and most existing tools are just too heavy and complex for small sites or solo devs to bother with.
So I built something that actually fits that world.
I'm a software dev by trade (not a security researcher), but I had a friend who's a professional pentester helping me make sure the logic is solid.
Here's a real scan report on crAPI (a deliberately vulnerable app used for security testing) so you can see the kind of output BattleTester produces https://drive.google.com/file/d/...
It's free to use. There's a queue since I'm keeping server costs sane as a one-man show, but give it a shot and tell me what you think. Brutal honesty very welcome 🙏
Report
How does the AI actually tailor its scans to a specific dataset without sending the data somewhere sketchy, and is it local or cloud?
Report
Maker
@feyza1144140 The entire tests I'm running are tests I built specifically, the ai don't have "full control" and have only a specific set of tools he can do (also depends on which specific test he runs)
usually its: 1. doing manual tests and gathering and categorizing the data 2. in some of the tests give the data to AI ONLY to report if found any issues, false positives and write the finding
Report
Finally tried BattleTester on a side project and the clean report was a nice surprise - no fluff, just the actual issue and where to fix it. Setup took maybe two minutes which is a first for me.
Report
Finally, a security tool that doesn't make me feel like I need a certification just to run it. The clean report was genuinely surprising—just the real issues without the false positive soup I'd given up on expecting.
How does the AI actually tailor its scans to a specific dataset without sending the data somewhere sketchy, and is it local or cloud?
@feyza1144140 The entire tests I'm running are tests I built specifically, the ai don't have "full control" and have only a specific set of tools he can do (also depends on which specific test he runs)
usually its:
1. doing manual tests and gathering and categorizing the data
2. in some of the tests give the data to AI ONLY to report if found any issues, false positives and write the finding
Finally tried BattleTester on a side project and the clean report was a nice surprise - no fluff, just the actual issue and where to fix it. Setup took maybe two minutes which is a first for me.
Finally, a security tool that doesn't make me feel like I need a certification just to run it. The clean report was genuinely surprising—just the real issues without the false positive soup I'd given up on expecting.