nowfound

Alternatives

Products that do what Website Security Testing (VAPT + OWASP) does

Because your first users shouldn’t be hackers.

  1. 1

    SaaS pen-testing that surpasses the level of ethical hackers

    2022

  2. 2

    Discover, Scan, and Secure every API at scale

    2025

  3. 3
    WebARX147

    Protect websites from plugin vulnerabilities

    2019

  4. 4

    AI-powered security scans for modern websites & AI apps.

    Jul 2026 · hackmywebsite.io

  5. 5

    10-point OWASP web security checklist in 1 click

    22d ago · github.com

  6. 6

    Scan any website for security flaws in one click

    Nov 2025

  7. 7

    Web & API VAPT to find vulnerabilities before hackers

    Apr 2026 · trustlayerlabs.co.in

  8. 8BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  9. 9

    Fully managed web application scanning & risk detection

    2020

  10. 10

    Website security scanner — 60 seconds, 75+ tests + features

    Jul 2026 · securewatchonline.com

  11. 11OT

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com

  12. 12MN

    This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers. Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking. It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability. I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that…

    Feb 2026 · github.com

  13. 13

    Find your app's critical vulnerabilities before attackers do

    Jun 2026 · pentestr.up.railway.app

  14. 14CF

    2012 · webscanservice.com

  15. 15

    Find vulnerabilities in your AI prompts before your users do

    26d ago · testmyprompt.net

  16. 16

    Free website security audit grade in 10 seconds

    Mar 2026 · vulnscan.tech

  17. 17

    You build. We secure. 🛡️🚀

    Apr 2026 · vaptinsights.com

  18. 18EY

    I built an open-source AI agent for security testing to find and fix vulnerabilities in your code. I’ve noticed how bad security vulnerabilities have gotten with everyone shipping AI code slop, so I wanted to build something that allows for vibe-coding at full speed without compromising security. Traditional security tools aren’t effective, and manual pen-testing can’t keep up with the rapidly growing AI code This tool runs your code dynamically, finds vulnerabilities, and validates them through actual exploitation. You can either run it against your codebase or enter your (or someone…

    2025 · github.com

  19. 19WS

    http://webscanner.tk/quickscan/ Hi! I made this project over the couse of a week to help teach myself more about Django and web app development. I am studying computer security in school and web security is one of my passions. It is a tool that helps web developers ensure that they have implemented helpful security mechanisms like HTTPOnly flags, X-Frame-Options, etc. There are hundreds of tools that offer to scan websites for things like cross-site scripting, mySQL injection, etc. This tool simply looks for information that is available via one or two GET requests (the headers, protocols,…

    2013

  20. 20

    Hosted vuln scanning with client-ready reports

    Jul 2026 · vulnscanners.com

  21. 21

    Major Updates for Enterprise Security Teams

    Oct 2025

  22. 22

    Free security scan that tells you exactly how to fix it

    Jun 2026

  23. 23

    Find AI vulnerabilities before hackers do

    Mar 2026 · promptbrake.com

  24. 24

    Secret scanning for shipped-too-fast websites

    Jan 2026

Ranked by how close each launch is in meaning, then by votes. Refine with a description →