API Scanner Pro is an open-source Python security and developer utility for browser-based API discovery, network inspection, heuristic threat analysis, and report generation.
Status: Active development. The scanner produces evidence and heuristic indicators for investigation; it does not provide definitive vulnerability or malware verdicts.
- Browser network interception with Playwright.
- Likely API endpoint detection from URL and response-content heuristics.
- Cookie, localStorage, and sessionStorage inspection.
- HTML metadata and security-header analysis.
- Deterministic URL/HTML threat heuristics, including IP hosts, suspicious TLDs, typosquatting patterns, suspicious forms, hidden iframes, and obfuscated JavaScript.
- Optional Shodan host intelligence.
- JSON, CSV, and standalone HTML report export.
- Tkinter desktop UI plus a scriptable CLI.
- Automated tests and GitHub Actions CI.
Api_Scanner_Bot/
βββ api_scanner/
β βββ cli.py # Scriptable command-line interface
β βββ main.py # Tkinter application entry point
β βββ config.py # Environment-based configuration
β βββ exceptions.py
β βββ logger.py
β βββ utils.py
β βββ scanner/ # Network capture, storage, metadata, models
β βββ security/ # Threat analysis and optional Shodan integration
β βββ exporters/ # JSON, CSV, HTML reporting
β βββ ui/ # Tkinter interface
βββ tests/
βββ docs/
βββ .github/
β βββ ISSUE_TEMPLATE/
β βββ pull_request_template.md
β βββ workflows/ci.yml
βββ CONTRIBUTING.md
βββ SECURITY.md
βββ LICENSE
βββ .env.example
βββ requirements.txt
βββ pyproject.toml
βββ README.md
Requirements: Python 3.11+ and Chromium installed by Playwright for browser scans.
git clone https://github.com/Skbindas/Api_Scanner_Bot.git
cd Api_Scanner_Bot
python -m venv .venv
# macOS/Linux
source .venv/bin/activate
# Windows: .venv\\Scripts\\activate
pip install -e ".[dev]"
playwright install chromiumOptional configuration is documented in .env.example.
The CLI supports reproducible local analysis and automation without launching the Tkinter UI.
api-scanner --help
api-scanner analyze-url https://example.com
api-scanner analyze-url https://example.com --json
api-scanner scan https://example.com
api-scanner scan https://example.com --export json csv htmlFor a visible browser, custom timeout, or output directory:
api-scanner scan https://example.com --output-dir ./artifacts --timeout 45 --headedThe CLI reuses the project's scanning and export components.
This project documents reproducible local usage instead of making unverifiable claims about external users or production traffic.
See docs/usage-example.md for an end-to-end workflow. The test suite covers configuration, models, utilities, threat analysis, exporters, and CLI argument parsing.
Run the local checks:
pytest -q
python -m compileall -q api_scanner
python -m api_scanner.cli --helpGitHub Actions runs the tests and CLI/package smoke checks on Python 3.11, 3.12, and 3.13.
For the current adoption/implementation evidence snapshot, see docs/oss-evidence.md.
Versioned releases are built from semantic Git tags. The repository contains an automated tagged-release workflow that builds the Python distribution and validates it with twine check.
The v2.0.0 release should be created only after the v2.0.0 tag is created on the validated main commit. See docs/release.md for the maintainer checklist.
- Enter an authorized target URL.
- Start the browser-based scan.
- Review captured requests and likely API endpoints.
- Review security indicators and metadata.
- Export JSON, CSV, or HTML reports.
The scanner can capture request/response metadata and browser storage from a target. Treat scan output as potentially sensitive.
- Only scan systems you own or have explicit permission to assess.
- Never commit API keys, session tokens, credentials, cookies, or private scan output.
- Review generated reports before sharing them.
- Read SECURITY.md for vulnerability reporting and safe-use guidance.
| Variable | Default | Purpose |
|---|---|---|
SHODAN_API_KEY |
empty | Optional Shodan host intelligence |
SCAN_TIMEOUT |
30 |
Page navigation timeout in seconds |
MAX_RETRIES |
3 |
Retry count |
RATE_LIMIT_DELAY |
1.0 |
Minimum delay between rate-limited requests |
OUTPUT_DIR |
scan_results |
Report output directory |
HEADLESS |
true |
Browser visibility |
LOG_LEVEL |
INFO |
Logging level |
pip install -e ".[dev]"
pytest -q
pytest -q tests/test_threat_analyzer.pyThe threat-analysis tests are deterministic and do not require a live target.
Contributions are welcome. Read CONTRIBUTING.md before opening an issue or pull request.
The repository includes structured bug/feature issue forms, a pull-request checklist, security guidance, and automated CI.
API Scanner Pro is released under the MIT License.
Repository: https://github.com/Skbindas/Api_Scanner_Bot