A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
-
Updated
Sep 14, 2026 - Python
A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
A stateful, dual-token API security scanner designed to hunt for complex authorization flaws like BOLA, BFLA, and Mass Assignment.
A lightweight, high-performance browser extension (Manifest V3) designed for penetration testers and ethical hackers. Features passive HTTP traffic inspection, automated IDOR/BOLA scoring, noise filtering, and AI-driven vulnerability analysis with PDF report generation. Built for ethical security research.
Automated web security testing tool designed to detect Insecure Direct Object References (IDOR) vulnerabilities in web applications
Automatically detect and test IDOR/BOLA vulnerabilities in real time using AI-powered object ID swapping during Burp Suite browsing sessions.
Burp Suite extension for automated multi-tenant IDOR/BOLA testing
To associate your repository with the idor-discovery topic, visit your repo's landing page and select "manage topics."