LeakRadar is an open-core DAST security engine for REST APIs. It detects Broken Object Level Authorization (BOLA/IDOR) flaws and exposed credentials with near-zero false positives using a pairwise token heuristic algorithm. Includes Executive PDF Reports, automated Python remediation code fixes, and Custom Agency Logo White-Labeling for pen-testers and vCISOs.
I built LeakRadar because existing vulnerability scanners generate too many false positives and struggle with complex BOLA/IDOR authorization flaws across multi-user REST APIs.
LeakRadar uses a pairwise token heuristic engine to replay requests across different identities, isolating true BOLA flaws with near-zero noise.
Key Features: - Free Open-Core CLI engine for security researchers - Executive PDF Audit Reports with CVSS 3.1 risk scores - Custom White-Labeled Agency Logo & Company branding for pen-testers & vCISOs - Automated Python remediation code fix recommendations
I'd love to hear your feedback, questions, and feature suggestions.
Hey Product Hunt!
I built LeakRadar because existing vulnerability scanners generate too many false positives and struggle with complex BOLA/IDOR authorization flaws across multi-user REST APIs.
LeakRadar uses a pairwise token heuristic engine to replay requests across different identities, isolating true BOLA flaws with near-zero noise.
Key Features:
- Free Open-Core CLI engine for security researchers
- Executive PDF Audit Reports with CVSS 3.1 risk scores
- Custom White-Labeled Agency Logo & Company branding for pen-testers & vCISOs
- Automated Python remediation code fix recommendations
I'd love to hear your feedback, questions, and feature suggestions.