Ross ROSS = Recommend OSS · open-source software intelligence for agents

Quitten/Autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests observed · 2026-08-28

github.com/Quitten/Autorize · Python observed · 2026-08-28

Health v2 · maintenance only

56/100

  • Activity 73
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4219
  • days_rel: n/a
  • days_push: 165
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1169 stars · 252 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web applications. It replays high-privileged user requests with low-privileged or unauthenticated contexts and analyzes responses to identify broken access controls such as IDORs.

Use cases

  • detect authorization bypasses in web apps
  • find IDOR vulnerabilities automatically
  • test role separation between admin and regular users
  • identify endpoints missing authentication
  • verify backend authorization logic consistency
  • automate access control testing during pentests

When to choose

  • you are a penetration tester or appsec engineer testing authenticated web applications
  • you need to automate authorization enforcement checks instead of manual request replay
  • you already use Burp Suite and want passive IDOR/broken access control detection

When to avoid

  • you are not using Burp Suite or cannot set up the Jython environment
  • you need automated scanning outside of an authenticated proxy-driven workflow
  • you require a standalone CLI or CI/CD-integrated DAST tool

Facets

plugin · maturity active

authorization security penetration-testing vulnerability-scanning http-client security penetration-testing web-development developer-tools cross-platform jvm python burp-suite burp-extension jython authorization-testing idor access-control bapp-store web-app-security

1 source

Member repositories

RepositoryRoleHealth v2
Quitten/Autorizemain56

For agents

markdown · JSON · MCP: product_card(name="Quitten/Autorize")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem