OWASP API Top 10 2023 + GraphQL security scanner for REST, GraphQL, and gRPC APIs. Detects BOLA/IDOR, BFLA, SSRF, introspection leaks, depth DoS, batching attacks, and auth bypass.
| Check | OWASP API Category | Severity |
|---|---|---|
| Broken Object Level Authorization (BOLA) | API1:2023 | 🔴 CRITICAL |
| Broken Authentication | API2:2023 | 🔴 CRITICAL |
| Broken Object Property Level Auth | API3:2023 | 🟠 HIGH |
| Unrestricted Resource Consumption | API4:2023 | 🟠 HIGH |
| Broken Function Level Authorization | API5:2023 | 🔴 CRITICAL |
| Unrestricted Access to Sensitive Flows | API6:2023 | 🟠 HIGH |
| Server Side Request Forgery (SSRF) | API7:2023 | 🟠 HIGH |
| Security Misconfiguration | API8:2023 | 🟡 MEDIUM |
| Improper Inventory Management | API9:2023 | 🟡 MEDIUM |
| Unsafe Consumption of APIs | API10:2023 | 🟡 MEDIUM |
| Check | Severity |
|---|---|
| Introspection Enabled | 🔴 CRITICAL |
| Depth/Breadth DoS | 🟠 HIGH |
| Batching Attack | 🟠 HIGH |
| Field-Level Auth Bypass | 🔴 CRITICAL |
| Alias Overloading | 🟡 MEDIUM |
git clone https://github.com/ridhinva/api-security-scanner.git
cd api-security-scanner
pip install requests
python3 api_security_scanner.py --target https://api.example.com --mode allFor authorized security testing only.