# flipkart-incubator/Astra

Automated Security Testing For REST API's

Repository: https://github.com/flipkart-incubator/Astra
Canonical: https://ross.abutalabs.com/products/astra
Language: Python
License: Apache-2.0
License Family: permissive
Topics: security, restapiautomation, python, owasp, penetration-testing-framework, postman-collection, ci-cd, sdlc, penetration-testing, security-automation
Last push: 2024-06-05T17:35:29+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3157, "days_push": 819, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2658, forks 413 (observed 2026-08-28T04:07:07.391797+00:00)

## What it is
Astra is an automated REST API security testing tool from Flipkart that detects vulnerabilities like SQL injection, XSS, broken authentication, JWT attacks, CSRF, and SSRF. It accepts Postman or Swagger collections as input, offers both CLI and web dashboard modes, and integrates into CI/CD pipelines.

## Use cases
- automated penetration testing of REST APIs
- scan Postman collection for security vulnerabilities
- integrate API security testing into CI/CD pipeline
- detect SQL injection and XSS in API endpoints
- test JWT and authentication flaws in APIs
- find CORS misconfigurations and rate limiting issues
- run API security scans from Swagger definitions

## When to choose
- you need automated REST API vulnerability scanning in Python
- you want to shift API security testing left in the SDLC
- you already have Postman or Swagger collections to scan
- you need both CLI and dashboard interfaces for API pentesting

## When to avoid
- you need to test GraphQL or SOAP APIs
- you require a maintained tool with recent updates and Python 3.10+ support
- you need GUI-driven manual penetration testing rather than automated scanning
- you need Windows support natively without Docker

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: penetration-testing, security, vulnerability-scanning, testing, ci-cd
- domain: security, penetration-testing, apis, developer-tools
- platform: python, cli
- tags: rest-api-security, postman-collection, swagger, owasp, security-automation, sdlc, api-scanning, dashboard, automation, linux, macos, docker, web-server

## Member repositories
- flipkart-incubator/Astra (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:07.391797+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:18:25.801968+00:00, confidence not recorded.
  - readme: https://github.com/flipkart-incubator/Astra (fetched 2026-08-28T04:07:07.391797+00:00, sha a7f53070d686)
- Data as of 2026-08-30T08:39:29.467469+00:00.
