{"repo":"Teycir/BurpAPISecuritySuite","free":true,"listed":false,"github":"https://github.com/Teycir/BurpAPISecuritySuite","clone":"git clone https://github.com/Teycir/BurpAPISecuritySuite.git","description":"Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.","language":"Python","stars":249,"topics":["ai-security","api-security","api-testing","bola","burp-extensions","burp-suite","fuzzing","graphql","idor","jwt"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Support Development If this project helps your work, support ongoing maintenance and new features. ETH Donation Wallet 0x11282eE5726B3370c8B480e321b3B2aA13686582 Scan the QR code or copy the wallet address above. BurpAPISecuritySuite Professional-grade Burp Suite extension for comprehensive API reconnaissance, intelligent fuzzing, and AI-powered security testing. Why One Extension with Multiple Tabs? BurpAPISecuritySuite consolidates functionality that would typically require 10+ separate extensions into a single, optimized extension. This architectural decision provides significant performance benefits: Memory Efficiency : Running multiple Burp extensions simultaneously creates substantial memory pressure. Each extension maintains its own state, UI components, and event listeners. A single extension with multiple tabs shares resources efficiently and reduces overall memory footprint. Reduced API Overhead : Burp's extension API processes callbacks from every loaded extension. With 10+ extensions, each HTTP request triggers callbacks across all extensions, creating multiplicative overhead. One extension means one callback chain, dramatically reducing CPU cycles and improving responsiveness. Shared Context : Integrated tabs share captured traffic data, eliminating redundant processing. The Recon tab captures once, and all other tabs (Fuzzer, Auth Replay, Passive Discovery, etc.) operate on the same dataset without re-parsing requests. Faster Startup : Loading one extension is s","default_branch":null,"files":null,"tree":[],"storefront":"/r/Teycir","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Teycir/BurpAPISecuritySuite/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}