Free Burp Suite AlternativesTop Vulnerability Scanners and other similar apps like Burp Suite

The best free alternative to Burp Suite is mitmproxy, which is also Open Source. If that doesn't suit you, our users have ranked more than 25 alternatives to Burp Suite and 19 is free so hopefully you can find a suitable replacement. Other interesting free alternatives to Burp Suite are Zed Attack Proxy (ZAP), Fiddler, SiteOne Crawler and HTTP Toolkit.

Copy a direct link to this comment to your clipboard
Burp Suite alternatives page was last updated

Alternatives list

  1. mitmproxy icon
     78 likes

    mitmproxy is an SSL-capable man-in-the-middle proxy for HTTP. It provides a console interface that allows traffic flows to be inspected and edited on the fly. It also features mitmdump, a commandline tool that provides a tcpdump-like interface for saving, viewing and...

    24 mitmproxy alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Mac
    • Windows
    • Linux
    • Flathub
    • Flatpak
     
  2. Fiddler icon
     206 likes

    Web Debugging Proxy that logs all HTTP(S) traffic for comprehensive analysis. It allows manipulation of traffic, supports scripting, and extends with .NET. Debugs virtually any application, implementing man-in-the-middle interception with self-signed certificates. Freeware, ideal for developers.

    48 Fiddler alternatives

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Windows
     
  3. SiteOne Crawler icon
     21 likes

    A free in-depth website analyzer providing audits of security, performance, SEO, accessibility and other technical aspects. Available as a desktop application for Windows/macOS/Linux and as a CLI tool for advanced users and CI/CD processes. It also includes an offline web page exporter.

    Cost / License

    • Free
    • Open Source (MIT)

    Application types

    Platforms

    • Mac
    • Windows
    • Linux
     
  4. HTTP Toolkit icon
     93 likes

    HTTP Toolkit is a beautiful, cross-platform & open-source HTTP(S) debugging proxy, analyzer & client, with built-in support for modern tools and automatic interception for clients from Docker to Android to iOS.

    51 HTTP Toolkit alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Android
    • iPhone
    • Docker
     
  5. Caido icon
     5 likes

    Caido is a cutting-edge web application security tool that enables users to efficiently identify and assess potential vulnerabilities in their web applications. It can be easily integrated into both personal and enterprise environments, making it adaptable to a wide range of...

    6 Caido alternatives

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Online
     
  6. w3af icon
     16 likes

    w3af is a Web Application Attack and Audit Framework.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Windows
    • Linux
     
  7. SecApps icon
     4 likes

    Find security vulnerabilities right from your browser. Experience the next generation security tools without the need to install any additional software.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Chrome OS
     
  8. Guardius icon
     1 like

    Guardius is a Software as a Service (SaaS) company designed to streamline and automate various IT needs for companies that operate their own websites or manage their own infrastructure. It is crucial for companies to safeguard their websites and infrastructure against potential...

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
     
  9. Golem Security Scanner is a powerful and intuitive website security scanner which uses a combination of proprietary and open source scanners to maximize the scan findings. Much less expensive for the paid version than other providers, with a free option which scans a portion of...

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Online
     
  10. nuclei icon
     2 likes

    Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.

    24 nuclei alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
     
  11. Probely icon
     16 likes

    Probely is a top-tier cloud-based DAST Scanner designed for DevOps, empowering Security and Development teams to work together to secure their web applications and APIs.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Online
     
12 of 19 Burp Suite alternatives