Security
▾
Vulnerabilities
Prompt Injection
BOLA / IDOR
Auth Bypass
JWT Misconfiguration
SSRF
Data Exposure
Rate Limiting
Mass Assignment
GraphQL Attacks
View all 60+
Frameworks
FastAPI
Express
Spring Boot
Django
NestJS
Rails
Laravel
Gin
ASP.NET
View all 30+
LLM Security
OpenAI
Anthropic
Google Gemini
Mistral
Meta Llama
LangChain
LlamaIndex
View all 15+
By Industry
Fintech
Healthcare
SaaS
IoT
By Protocol
REST
GraphQL
gRPC
WebSocket
CWE Database
CWE-89: SQL Injection
CWE-79: XSS
CWE-287: Auth Bypass
CWE-200: Data Exposure
CWE-918: SSRF
CWE-502: Deserialization
View all 200+
Attack Techniques
Credential Stuffing
JWT Cracking
Prompt Injection
SSRF Metadata
IDOR Enumeration
View all 40+
Scan Your API Now — Free
Compliance
▾
Standards
OWASP API Top 10
PCI-DSS
HIPAA
SOC 2
GDPR
ISO 27001
NIST
CIS
Popular Checks
OWASP: Auth Bypass
PCI-DSS: Data Exposure
HIPAA: PII Leakage
SOC 2: Encryption
GDPR: Data Protection
Regulations
GDPR (EU)
CCPA (California)
LGPD (Brazil)
PSD2 (EU)
DORA (EU)
NIS2 (EU)
PIPL (China)
CMMC (US DoD)
FedRAMP (US)
View all 20+
Solutions
▾
By use case
Pre-launch API gate
CI/CD security gate
Pre-merge PR check
Post-deploy verification
New endpoint discovery
Pre-production scan
View all use cases
By role
For CISOs
For DevSecOps
For AppSec engineers
For Platform engineers
For AI / ML engineers
For Security architects
View all roles
Scan Your API Now — Free
Compare
▾
middleBrick vs
vs Burp Suite
vs OWASP ZAP
vs 42Crunch
vs StackHawk
vs APIsec
vs Akto
All comparisons
Alternatives to
Alternatives to Burp Suite
Alternatives to OWASP ZAP
Alternatives to 42Crunch
Alternatives to StackHawk
Alternatives to Snyk
Alternatives to Salt
All alternatives
Case Studies
Pricing
Docs
EN
▾
EN
ES
PT
DE
FR
Get Started
Case Studies
CASE STUDIES
API Security Case Studies
Real security audits of popular public APIs. Real findings. Real remediation.
Public API audits
FakeStoreAPI
medium
C · 75/100
ReqRes
medium
C · 73/100
DummyJSON
info
B · 75/100
HTTPBin
info
B · 82/100
PokéAPI
info
B · 76/100
JSONPlaceholder
medium
C · 73/100
Scan Your APIs Now
Learn how it works