
No source code
Test a web application from its URL
DerScanner sends requests to the running application and reads the responses. Vendor, contractor and in-house apps go through the same test.
of breaches start with an exploited vulnerability
Verizon DBIR 2026
to fix a high or critical application flaw
Edgescan 2026
of applications carry flaws open for over a year
Veracode SoSS 2026
year-over-year rise in high-risk vulnerabilities
Veracode SoSS 2026

No source code
DerScanner sends requests to the running application and reads the responses. Vendor, contractor and in-house apps go through the same test.

Behind a login
Six methods: login and password, bearer token, headers, login form, NTLM or Kerberos. Header-based login covers complex flows across several resources after one manual sign-in.

Dynamic pages and OpenAPI
Endpoints described in an OpenAPI definition enter the scan, attached as a JSON

Proof for developers
Each finding carries the request, the server response, a description and remediation advice. Findings go to Jira as tasks.

Inside the network
DerScanner installs on-premise, including air-gapped networks. Application URLs, credentials and results stay on internal servers.

Audit evidence
Reports export to PDF, HTML, CSV or JSON with scan history, scan comparison and the event log. They carry a custom logo and go out by email.
STAGING
Aggressive and active attack modes run where they belong — against staging and pre-production, not against live users.
RELEASE
The release gate runs the same web application security testing the team already trusts, as a pipeline step.
IN PRODUCTION
Production stays covered without aggressive payloads: detection-first scanning and scheduled retests.
When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the capabilities of the product. DerScanner addresses our main challenge of checking the health of our product's code.
DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.
We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.
Web application security testing checks a web application for vulnerabilities an attacker could exploit, such as injections, XSS, authentication flaws, and server misconfigurations. Black-box testing sends requests to the running application and analyzes the responses without access to the source code. Source code analysis finds flaws before release. DerScanner runs both in one platform, on-premise or in the cloud.
It finds vulnerabilities that show up in the running application: injection flaws, cross-site scripting (XSS), authentication gaps, session handling errors and server misconfigurations. DerScanner classifies each finding by CWE, WASC, OWASP Top 10 and OWASP WSTG. Every finding comes with the request and server response that triggered it, a description and remediation advice.
DAST is one method of web application security testing: it tests the running application from the outside. Web application security testing is the wider task and can also include source code analysis, open-source dependency checks, and manual penetration testing. DerScanner covers DAST, SAST, and SCA in one platform. The DAST page describes the dynamic scanner in detail.
DerScanner logs in with a login and password, a bearer token, request headers, a login form, NTLM, or Kerberos. For complex flows across several resources, log in manually, copy the request headers, and paste them into the scan settings. The headers stay static during the scan, so token lifetime needs to cover the full scan. The login-form method covers single-step username and password forms.
API endpoints enter the scan through an OpenAPI definition in JSON, attached as a file
No. Automated web application security testing finds common vulnerabilities quickly and repeats on every release. A manual penetration test goes deeper into business logic and chained attacks. Running DerScanner before a pentest clears the known findings first, so pentesters spend their hours on flaws a scanner cannot model.
A DerScanner report lists vulnerabilities with severity, status, description, recommendations, and reference links. Optional parts include request and response data, the event log with comments and actions, scan history, security level dynamics, and a comparison with an earlier scan. Reports export to PDF, HTML, CSV, or JSON and can be sent by email from the interface.
The DerScanner command-line tool and REST API create projects, start scans with login settings, check scan status, and export reports, so any CI/CD pipeline can call them after a deployment. Autoscan reruns tests on a schedule for applications outside the pipeline. Scan comparison then shows which vulnerabilities are new, remaining, or fixed.
Yes. DerScanner installs on-premise, including air-gapped networks, and the scan runs from an agent that reaches the application inside the network. Intranet portals, back-office tools, and staging environments are tested without exposing them to an outside service. Application URLs, credentials, and results stay on internal servers.
Prefer email? company@derscanner.com