DerScanner DAST

Test live web applications from the outside, including pages behind a login and API endpoints from an OpenAPI definition. Every finding comes with the request and response behind it.
31%

of breaches start with an exploited vulnerability

Verizon DBIR 2026

55 days

to fix a high or critical application flaw

Edgescan 2026

49%

of applications carry flaws open for over a year

Veracode SoSS 2026

36%

year-over-year rise in high-risk vulnerabilities

Veracode SoSS 2026

  • Five login methods, including header-based login for complex flows
  • AJAX spider for dynamic content, OpenAPI import for API endpoints
  • On-premise and air-gapped deployment
  • Reports in PDF, HTML, CSV and JSON

Securing the world's best teams

Which web application testing tasks does DerScanner cover?

Home page, URL field and Start Scan button

No source code

Test a web application from its URL

DerScanner sends requests to the running application and reads the responses. Vendor, contractor and in-house apps go through the same test.

Scan Settings, Authorization tab with the method list open

Behind a login

Scan the pages behind a login

Six methods: login and password, bearer token, headers, login form, NTLM or Kerberos. Header-based login covers complex flows across several resources after one manual sign-in.

Scan Settings, General tab: AJAX spider toggle and OpenAPI URL field

Dynamic pages and OpenAPI

Cover dynamic pages and OpenAPI endpoints

Endpoints described in an OpenAPI definition enter the scan, attached as a JSON

Detailed Results with the request and response panel open

Proof for developers

Attach the HTTP exchange to every finding

Each finding carries the request, the server response, a description and remediation advice. Findings go to Jira as tasks.

Export Report settings

Audit evidence

Export scan history as audit evidence

Reports export to PDF, HTML, CSV or JSON with scan history, scan comparison and the event log. They carry a custom logo and go out by email.

Where does web application scanning sit in the pipeline?

STAGING

Aggressive and active attack modes run where they belong — against staging and pre-production, not against live users.

  • Aggressive and active attack modes run attacks against staging and pre-production.
  • Excluded URLs stay out of every scan.

RELEASE

The release gate runs the same web application security testing the team already trusts, as a pipeline step.

  • GitLab CI runs the scan as a pipeline step; other pipelines start it through the CLI or REST API.
  • Scan comparison shows which vulnerabilities are new, remaining and fixed against an earlier scan.

IN PRODUCTION

Production stays covered without aggressive payloads: detection-first scanning and scheduled retests.

  • Standard mode looks for vulnerabilities without attacking the application.
  • Autoscan reruns the test on a schedule with saved login data.

Teams already shipping with DerScanner

When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the capabilities of the product. DerScanner addresses our main challenge of checking the health of our product's code.

DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.

We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.

Frequently asked questions

Web application security testing checks a web application for vulnerabilities an attacker could exploit, such as injections, XSS, authentication flaws, and server misconfigurations. Black-box testing sends requests to the running application and analyzes the responses without access to the source code. Source code analysis finds flaws before release. DerScanner runs both in one platform, on-premise or in the cloud.

Run a proof of concept on a web application

  • Run a proof of concept on one web application, internal or public.
  • Install on internal servers, on-premise or fully air-gapped.
  • Export the first report with the request and response behind each finding.

Prefer email? company@derscanner.com