← TrendWatcher
GitHub Trending
6/10

AuthProbe Cloud — Hosted Multi-Tenant BOLA/IDOR Scanning as a Service

A managed SaaS version of AuthProbe that lets small security teams and HR-tech startups run continuous, multi-identity authorization tests against their own APIs without maintaining the toolchain themselves — with Slack alerts and a dashboard that non-security execs can actually read.

Target user

CTOs and lone security engineers at HR-tech startups and SaaS companies handling sensitive multi-tenant data

Features
  • Schedule recurring scans against your OpenAPI spec and CI gate — no infra to manage
  • Executive dashboard translating findings into business risk ("Bob's recruiter at ACME Staffing can read Alice's candidates")
  • Slack and PagerDuty alerts with evidence payloads and reproducible curl commands
  • Compliance evidence exports mapped to OWASP API Top 10 and SOC 2 access-control criteria
Why now

AuthProbe is trending on GitHub because BOLA has been OWASP's #1 API risk for years and recent incidents (McHire) made it mainstream news — small teams now feel pressure they can't meet with manual Burp sessions.

Signals · overall 6/10
Demand
7/10

OWASP API #1 since 2019, BOLA is in ~40% of API attacks (Salt Security), McHire made it mainstream news, AuthProbe has 140★/90 forks on GitHub — real but small traction on the seed project.GitHub - jbarach2012/AuthProbeOWASP API1:2023 Broken Object Level Authorization

Whitespace
4/10

Crowded adjacent space: Escape.tech already markets BOLA/IDOR/BFLA detection as a SaaS with 140+ tests, Invicti documents multi-session IDOR/BOLA scanning, Salt Security and StackHawk cover the same need — direct niche is narrow.Escape: AI-Powered Offensive Security PlatformAPI access control testing overview | Invicti Platform

Monetization
6/10

HR-tech and SaaS startups under SOC2/privacy pressure will pay, and Escape/AWS Marketplace shows tiered per-app pricing is viable — but free open-source AuthProbe cannibalizes the bottom tier and Escape/Invicti compete on the top.Escape Technologies pricing: what are the AWS Marketplace tiers (15/60)Discover Escape's features to secure all your APIs

Longevity
9/10

BOLA has been the OWASP API #1 since 2019 and Salt Security notes it stays in ~40% of attacks; multi-tenant SaaS data is permanent, and LLM-generated code increases API surface area rather than fixing auth bugs.Broken Object Level Authorization (BOLA) - API1:2023 - Salt Security

Feasibility
5/10

Build is straightforward on top of AuthProbe, but the real work is multi-tenant secret/identity orchestration, scheduled scanning, Slack plumbing, and an exec-readable dashboard — meaningful but not novel engineering.GitHub - jbarach2012/AuthProbe

jbarach2012/AuthProbe · ★ 140GitHub Trending · 2026-07-16 (8d ago)