Verune

Plugin

42crunch-api-security-testing

Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language. Designed for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime testing to ensure your APIs behave securely in real conditions. With a simple audit to scan to remediate to validate loop, developers can identify issues early, fix them with confidence, and verify that security requirements are met before deployment. The plugin integrates seamlessly into Claude Code, allowing teams to embed API security directly into their development process without switching tools. Key capabilities include static security audit of OpenAPI specifications with scored findings, detection of OWASP API Security risks including authorization flaws like BOLA and BFLA, live API scanning for conformance and runtime behavior validation, AI-assisted remediation with user-controlled changes, an end to end security testing pipeline combining audit and scan, and automatic generation of OpenAPI specifications from source code. Whether you are working with existing APIs or generating new ones, 42Crunch helps ensure that security is built in from the start and continuously validated throughout development.

Analysed
Last observed

What the code does

Static analysis found none of the capabilities we track, such as shell commands, network requests or file writes, in the latest version.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

1 finding from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment