Vooki Pro helps security teams find, validate and fix vulnerabilities faster — a DAST desktop app for web applications and REST APIs, with every scan running locally on your own machine.
Every feature unlocked for 14 days · No credit card required
Mapped to the standards your auditors ask for
Manual testing can't keep up with release cadence, and most scanners hand you noise instead of evidence.
A manual assessment lands once a quarter while your team ships weekly. Everything between those two dates goes to production untested.
Timing-based false positives, the same missing header filed 400 times, no request/response evidence. Triage costs more hours than the scan saved.
Staging behind a VPN, an internal admin app, a client's environment under NDA. Cloud scanners need a public target and a data-processing agreement you may never get.
Discovery, authentication, attack, triage, retest and reporting — in one desktop app, with no server to stand up.
A six-step wizard walks you from target to results: discovery by quick seed, browser recording, crawl or hybrid, with an optional headless pass that captures background XHR endpoints. Depth, URL and time budgets included.
Target → Discovery → Auth → Policy → Schedule → ReviewImport an OpenAPI v2/v3 spec, a Postman collection or a HAR file, or build requests by hand in the workspace — projects, folders, environments, variables and bulk auth. Then scan for BOLA, BFLA, mass assignment and GraphQL abuse.
OpenAPI · Postman · HARA local language model triages findings and prioritises parameters and payloads. It downloads once and runs on your machine — no scan content is ever sent to a third-party AI service.
Runs entirely offlineBrowse findings across every scan, filter by severity, type or target, and read the full HTTP request and response with the injected payload highlighted. Fixed it? Retest re-runs the exact detector and returns a verdict.
Still Vulnerable / Fixed / Needs ReviewExport to PDF, HTML, Word (DOCX) or JSON. Standard reports carry an executive summary, risk score and per-finding evidence; compliance reports map control by control across seven frameworks.
4 export formats · 7 frameworksRun scans on a cron expression or a simple every-N-hours interval. Export any wizard-configured scan as a JSON config and replay it headlessly from the command line, with reports and a complete .vpscan data file written as build artefacts.
Headless CLI · JSON configEnter a URL or import an API spec, then set scope — same host, same domain or a custom host list, with include and exclude patterns. Authenticate with a form login, bearer token, API key, basic auth, OAuth2 or a recorded browser session.
Pick a policy — Default, Quick, OWASP Top 10, API Surface or your own — and a speed preset from stealth to aggressive. Every non-timing attack runs first, then a timing-only pass skips whatever is already confirmed.
Review findings with full HTTP evidence and reproduction steps, mark false positives, override severity, file a ticket in Jira or GitHub, and export a standard or compliance report when you're done.
Test the connection, pick a project, repository or team, and file a finding as a ticket in one click. Alerts land in Slack or any webhook you point at.
304 active attack checks plus 177 version and outdated-component fingerprints, all selectable individually when you build a custom policy.
SQL and blind SQL, NoSQL, XXE, XPath, LDAP, OS command, SSTI, SSI, CRLF, host header, GraphQL, expression language, ORM, HPP and XSLT — plus reflected, stored, DOM, mutation, SVG and header-based cross-site scripting.
29 checksIDOR, BFLA, path traversal, forced browsing, privilege escalation and method override, alongside default credentials, user enumeration, weak password policy and the full JWT family — alg none, weak alg, algorithm confusion, jku and kid.
24 checksBOLA, BOPLA, BFLA, mass assignment, unrestricted resource consumption, GraphQL introspection and DoS, API misconfiguration, inventory and versioning issues — mapped to the OWASP API Top 10.
12 checksHeader, cookie, CORS, SRI and outdated-dependency issues are consolidated into one finding per host, origin, cookie or dependency — not one per crawled URL.
Timing-based attacks run in a separate second pass that skips anything already confirmed, so network jitter doesn't turn into a critical finding.
WAF and CDN detection, auth-health checks and session-expiry detection warn you when a scan is being blocked or the session died halfway through.
Start with a 14-day full-feature trial, then activate a licence key. No per-scan metering, no per-target billing.
Every feature unlocked for 14 days, so you can evaluate the real thing before you buy.
For a fixed engagement or a half-year assessment cycle.
For teams running continuous, scheduled testing all year.
Activation limits and licence duration are set on your account. Need more than 10 seats? Talk to us about custom pricing.
Start your 14-day trial, point Vooki Pro at an application you're allowed to test, and see what a two-phase DAST run turns up.
Signed and notarized for macOS · Windows installer · Linux AppImage
Tell us where to send your licence key and installer. Every feature is unlocked for 14 days — no credit card required.
By requesting a trial you agree to our Terms & Privacy Policy, and to only scan systems you are authorised to test.