OpenAPI 3.x specification security analysis module.
Static analysis of API specifications for security issues:
- OpenAPI discovery - Automatic spec file detection
- 9 security analyzers - Authentication, authorization, data exposure, etc.
- Contract integrity - Schema validation and reference resolution
- Authentication Analyzer - Weak or missing authentication
- Authorization Analyzer - Access control issues
- Data Exposure Analyzer - Sensitive data in responses
- Design Analyzer - API design anti-patterns
- Input Validation Analyzer - Schema validation gaps
- OAuth Analyzer - OAuth flow security issues
- Resource Restriction Analyzer - Rate limiting, pagination
- Security Headers Analyzer - Missing security headers
- Security Misconfiguration Analyzer - Configuration issues
- OpenAPI 3.0
- OpenAPI 3.1
- Swagger 2.0 (limited support)
vulnera api . # CLI usage - auto-detects openapi.yaml/spec filesAGPL-3.0-or-later. See LICENSE for details.