Home / Application Protection / Application Security

Application Security

Secure your applications with robust security measures. Protect against vulnerabilities and threats effectively.

Try these 256 AI Application Security Tools

StaCoAn
Free

StaCoAn

BunkerWeb is a next-generation and open-source Web Application Firewall (WAF) with seamless integration and user-friendly customization options.

Stowaway
Free

Stowaway

Static security code scanner (SAST) for Node.js applications with Docker support and integrations with Slack.

StepSecurity
Free

StepSecurity

An application security platform that provides runtime threat modeling, vulnerability management, and automated remediation workflows with a focus on identifying exploitable vulnerabilities in production environments.

Subresource Integrity (SRI)
Free

Subresource Integrity (SRI)

Automatically redirect users from www to non-www for a secure connection.

Sucuri Website Firewall (WAF)
Free

Sucuri Website Firewall (WAF)

API Security is a comprehensive solution that provides continuous discovery, vulnerability assessment, threat detection, compliance monitoring, dynamic testing, and remediation capabilities to protect APIs against various threats and vulnerabilities.

SUPER Android Analyzer
Free

SUPER Android Analyzer

Curiefense is an application security platform that protects against various threats and offers community involvement.

Symbiotic Security
Free

Symbiotic Security

DOMPurify is a fast XSS sanitizer for HTML, MathML, and SVG.

Talisman
Free

Talisman

A self-managed static code analysis platform that conducts continuous inspection of codebases to identify security vulnerabilities, bugs, and code quality issues.

TeejLab API Security Manager
Free

TeejLab API Security Manager

A self-managed static code analysis platform that conducts continuous inspection of codebases to identify security vulnerabilities, bugs, and code quality issues.

Tenable Web App Scanning
Free

Tenable Web App Scanning

Backslash Security is an application security platform that uses reachability analysis to enhance SAST and SCA, prioritize vulnerabilities, and provide remediation guidance.

TerraGoat
Free

TerraGoat

Detect users' operating systems and perform redirection with Apache mod_rewrite.

Tetragon
Free

Tetragon

A tool for identifying potential security vulnerabilities in dependency configurations by checking for lingering free namespaces for private package names.

The Matasano Crypto Challenges
Free

The Matasano Crypto Challenges

FlowDroid is a context-, flow-, field-, object-sensitive and lifecycle-aware static taint analysis tool for Android applications.

The Update Framework (TUF)
Free

The Update Framework (TUF)

Goof is a vulnerable Node.js demo application that includes a series of vulnerabilities and exploits

ThreatLocker Platform
Free

ThreatLocker Platform

QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.

Threatspy
Free

Threatspy

JAADAS is a powerful tool for static analysis of Android applications, providing features like API misuse analysis and inter-procedure dataflow analysis.

timing_attack
Free

timing_attack

An API security and governance platform that provides discovery, security testing, compliance monitoring and lifecycle management capabilities for enterprise API implementations.

Traceable API Security Platform
Free

Traceable API Security Platform

A static code analysis tool for parsing common data formats to detect hardcoded credentials and dangerous functions.

Tracee
Free

Tracee

DerScanner is a comprehensive application security testing platform that combines SAST, DAST, MAST, SCA, and Binary Analysis capabilities with support for on-premises deployment and CI/CD integration.

Tromzo Product Security Operating Platform
Free

Tromzo Product Security Operating Platform

A tool for dynamic analysis of mobile applications in a controlled environment.

UglifyJS 3
Free

UglifyJS 3

Qwiet AI is an application security platform that combines SAST, SCA, container security, secrets detection, and SBOM scanning with AI-powered vulnerability prioritization and automated fix generation.

URL Redirect from www to non-www
Free

URL Redirect from www to non-www

Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.