Skip to content

Latest commit

Β 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

API Scanner Pro v2.0

Python 3.11+ License MIT Version 2.0

API Scanner Pro is an open-source Python security and developer utility for browser-based API discovery, network inspection, heuristic threat analysis, and report generation.

Status: Active development. The scanner produces evidence and heuristic indicators for investigation; it does not provide definitive vulnerability or malware verdicts.

Features

  • Browser network interception with Playwright.
  • Likely API endpoint detection from URL and response-content heuristics.
  • Cookie, localStorage, and sessionStorage inspection.
  • HTML metadata and security-header analysis.
  • Deterministic URL/HTML threat heuristics, including IP hosts, suspicious TLDs, typosquatting patterns, suspicious forms, hidden iframes, and obfuscated JavaScript.
  • Optional Shodan host intelligence.
  • JSON, CSV, and standalone HTML report export.
  • Tkinter desktop UI plus a scriptable CLI.
  • Automated tests and GitHub Actions CI.

Architecture

Api_Scanner_Bot/
β”œβ”€β”€ api_scanner/
β”‚   β”œβ”€β”€ cli.py                   # Scriptable command-line interface
β”‚   β”œβ”€β”€ main.py                  # Tkinter application entry point
β”‚   β”œβ”€β”€ config.py                # Environment-based configuration
β”‚   β”œβ”€β”€ exceptions.py
β”‚   β”œβ”€β”€ logger.py
β”‚   β”œβ”€β”€ utils.py
β”‚   β”œβ”€β”€ scanner/                 # Network capture, storage, metadata, models
β”‚   β”œβ”€β”€ security/                # Threat analysis and optional Shodan integration
β”‚   β”œβ”€β”€ exporters/               # JSON, CSV, HTML reporting
β”‚   └── ui/                      # Tkinter interface
β”œβ”€β”€ tests/
β”œβ”€β”€ docs/
β”œβ”€β”€ .github/
β”‚   β”œβ”€β”€ ISSUE_TEMPLATE/
β”‚   β”œβ”€β”€ pull_request_template.md
β”‚   └── workflows/ci.yml
β”œβ”€β”€ CONTRIBUTING.md
β”œβ”€β”€ SECURITY.md
β”œβ”€β”€ LICENSE
β”œβ”€β”€ .env.example
β”œβ”€β”€ requirements.txt
β”œβ”€β”€ pyproject.toml
└── README.md

Installation

Requirements: Python 3.11+ and Chromium installed by Playwright for browser scans.

git clone https://github.com/Skbindas/Api_Scanner_Bot.git
cd Api_Scanner_Bot
python -m venv .venv
# macOS/Linux
source .venv/bin/activate
# Windows: .venv\\Scripts\\activate
pip install -e ".[dev]"
playwright install chromium

Optional configuration is documented in .env.example.

CLI

The CLI supports reproducible local analysis and automation without launching the Tkinter UI.

api-scanner --help
api-scanner analyze-url https://example.com
api-scanner analyze-url https://example.com --json
api-scanner scan https://example.com
api-scanner scan https://example.com --export json csv html

For a visible browser, custom timeout, or output directory:

api-scanner scan https://example.com --output-dir ./artifacts --timeout 45 --headed

The CLI reuses the project's scanning and export components.

Reproducible usage evidence

This project documents reproducible local usage instead of making unverifiable claims about external users or production traffic.

See docs/usage-example.md for an end-to-end workflow. The test suite covers configuration, models, utilities, threat analysis, exporters, and CLI argument parsing.

Run the local checks:

pytest -q
python -m compileall -q api_scanner
python -m api_scanner.cli --help

GitHub Actions runs the tests and CLI/package smoke checks on Python 3.11, 3.12, and 3.13.

For the current adoption/implementation evidence snapshot, see docs/oss-evidence.md.

Release process

Versioned releases are built from semantic Git tags. The repository contains an automated tagged-release workflow that builds the Python distribution and validates it with twine check.

The v2.0.0 release should be created only after the v2.0.0 tag is created on the validated main commit. See docs/release.md for the maintainer checklist.

GUI workflow

  1. Enter an authorized target URL.
  2. Start the browser-based scan.
  3. Review captured requests and likely API endpoints.
  4. Review security indicators and metadata.
  5. Export JSON, CSV, or HTML reports.

Security and privacy

The scanner can capture request/response metadata and browser storage from a target. Treat scan output as potentially sensitive.

  • Only scan systems you own or have explicit permission to assess.
  • Never commit API keys, session tokens, credentials, cookies, or private scan output.
  • Review generated reports before sharing them.
  • Read SECURITY.md for vulnerability reporting and safe-use guidance.

Configuration

Variable Default Purpose
SHODAN_API_KEY empty Optional Shodan host intelligence
SCAN_TIMEOUT 30 Page navigation timeout in seconds
MAX_RETRIES 3 Retry count
RATE_LIMIT_DELAY 1.0 Minimum delay between rate-limited requests
OUTPUT_DIR scan_results Report output directory
HEADLESS true Browser visibility
LOG_LEVEL INFO Logging level

Development

pip install -e ".[dev]"
pytest -q
pytest -q tests/test_threat_analyzer.py

The threat-analysis tests are deterministic and do not require a live target.

Contributing

Contributions are welcome. Read CONTRIBUTING.md before opening an issue or pull request.

The repository includes structured bug/feature issue forms, a pull-request checklist, security guidance, and automated CI.

License

API Scanner Pro is released under the MIT License.

Maintainer

Repository: https://github.com/Skbindas/Api_Scanner_Bot

About

# API Scanner Bot πŸ” ## Overview / ΰ€ͺΰ€°ΰ€Ώΰ€―ΰ₯‹ΰ€œΰ€¨ΰ€Ύ ΰ€΅ΰ€Ώΰ€΅ΰ€°ΰ€£ API Scanner Bot is a powerful tool designed to analyze websites, detect API endpoints, and assess security vulnerabilities. It provides comprehensive information about network requests, storage data, and potential security risks.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages