aicoolies logo
StackHawk logo
StackHawk logo

StackHawk

Shift-left DAST platform built for CI/CD pipeline integration

verified Jul 15, 2026

StackHawk is a dynamic application security testing platform designed for CI/CD pipeline integration. It tests running web applications and APIs for OWASP Top 10 vulnerabilities including SQL injection, XSS, and authentication flaws during the development process. Built on ZAP with a developer-friendly CLI and YAML configuration, it provides actionable findings with reproducer requests and fix guidance.

StackHawk was purpose-built for the shift-left security model where security testing runs as part of the development workflow rather than as a separate gate before production. The platform provides a CLI tool that developers run locally or in CI/CD pipelines to test running applications for OWASP Top 10 vulnerabilities. Built on top of the established OWASP ZAP scanning engine, StackHawk adds developer experience improvements including YAML-based configuration, API-aware scanning, and findings presented with one-click reproducers.

The CI/CD integration is StackHawk's defining capability. Pipeline plugins for GitHub Actions, GitLab CI, Jenkins, CircleCI, and other CI providers enable automated security testing on every pull request. Scan results appear as PR comments with severity ratings and direct links to detailed findings, creating a feedback loop where developers fix security issues alongside functional changes. Custom scan configurations per environment enable different testing profiles for development, staging, and production.

StackHawk scans REST APIs, GraphQL endpoints, gRPC services, and traditional web applications with authentication support that handles OAuth, session tokens, API keys, and custom auth schemes. Each finding includes a curl command that reproduces the vulnerability, making it simple for developers to verify the issue and confirm the fix. The triaging workflow allows teams to mark findings as false positives, accepted risks, or prioritized fixes, maintaining a clean backlog of actionable security work.

Pricing

Free for one application; Pro from $35/dev/month

Platforms

CLI, GitHub Actions, GitLab CI, any CI/CD, Docker

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

ToolHive mascot logo

ToolHive

Run and govern MCP servers across desktop, CLI and Kubernetes

Open-source MCP runtime and governance platform that runs servers in isolated containers, curates registries, enforces access policies, and operates gateways across desktop, CLI, and Kubernetes.

Open Source
Anamorpher parent Trail of Bits mark

Anamorpher

Craft image-scaling prompt-injection payloads to red-team multimodal AI systems

Open-source red-team toolkit from Trail of Bits that generates image-scaling attack payloads — images that look benign at full resolution but reveal a hidden prompt injection after a multimodal system downsamples them.

freeOpen Source
cai

CAI (Cybersecurity AI)

AI agent framework for offensive security and penetration testing

Alias Robotics' agent framework for building AI-driven offensive-security workflows — reconnaissance, exploitation, privilege escalation, and lateral movement — with multi-agent handoffs and human-in-the-loop control. Source-available, but the core is licensed for non-commercial research use only.

freemiumTelemetry
MEDUSA logo

MEDUSA

AI-first security scanner for LLM, agent, MCP, and RAG codebases

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

Open Source
iFixAi logo

iFixAi

Open-source diagnostic for AI operational misalignment

iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.

Open Source
Inspect AI parent UK AISI mark

Inspect AI

UK AI Security Institute framework for LLM safety evaluations

Inspect AI is an MIT-licensed framework from the UK AI Security Institute for running large language model evaluations, including tool use, multi-turn dialogue, model-graded scoring, and reusable evaluation tasks.

Open Source

Used in Stacks

Comparisons

StackHawk vs Snyk — CI/CD-Native DAST vs Developer Security Platform

StackHawk and Snyk both shift security left into the development workflow but cover different security domains. StackHawk specializes in dynamic application security testing that finds runtime vulnerabilities by scanning running applications during CI/CD. Snyk provides a broader developer security platform covering dependency vulnerabilities, container security, infrastructure as code scanning, and code analysis across the entire software supply chain.

StackHawkSnyk

FAQ

What is StackHawk?

StackHawk is a dynamic application security testing platform designed for CI/CD pipeline integration. It tests running web applications and APIs for OWASP Top 10 vulnerabilities including SQL injection, XSS, and authentication flaws during the development process. Built on ZAP with a developer-friendly CLI and YAML configuration, it provides actionable findings with reproducer requests and fix guidance.

Is StackHawk free?

Yes — StackHawk is open source and free to use. Free for one application; Pro from $35/dev/month

Is StackHawk still maintained?

Yes — StackHawk is active. Its listing was last verified on July 15, 2026.

What are the best StackHawk alternatives?

The top editor-verified StackHawk alternatives are Escape, Sonatype Lifecycle.