Quitten/Autorize
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests observed · 2026-08-28
Health v2 · maintenance only
56/100
- Activity 73
- Release rhythm 8
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4219
- days_rel: n/a
- days_push: 165
- n_releases_24m: 0
Adoption not part of the score
1169 stars · 252 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web applications. It replays high-privileged user requests with low-privileged or unauthenticated contexts and analyzes responses to identify broken access controls such as IDORs.
Use cases
- detect authorization bypasses in web apps
- find IDOR vulnerabilities automatically
- test role separation between admin and regular users
- identify endpoints missing authentication
- verify backend authorization logic consistency
- automate access control testing during pentests
When to choose
- you are a penetration tester or appsec engineer testing authenticated web applications
- you need to automate authorization enforcement checks instead of manual request replay
- you already use Burp Suite and want passive IDOR/broken access control detection
When to avoid
- you are not using Burp Suite or cannot set up the Jython environment
- you need automated scanning outside of an authenticated proxy-driven workflow
- you require a standalone CLI or CI/CD-integrated DAST tool
Facets
plugin · maturity active
authorization security penetration-testing vulnerability-scanning http-client security penetration-testing web-development developer-tools cross-platform jvm python burp-suite burp-extension jython authorization-testing idor access-control bapp-store web-app-security
1 source
- readme: https://github.com/Quitten/Autorize · fetched 2026-08-28 · 2f9da19e873f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Quitten/Autorize | main | 56 |
For agents
markdown · JSON · MCP: product_card(name="Quitten/Autorize")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem