Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/restler-fuzzer

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services. observed · 2026-08-28

github.com/microsoft/restler-fuzzer · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

71/100

  • Activity 86
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2231
  • days_rel: n/a
  • days_push: 84
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2939 stars · 331 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

RESTler is the first stateful REST API fuzzing tool, automatically testing cloud services through their REST APIs to find security and reliability bugs. It infers producer-consumer dependencies from OpenAPI specifications and generates request sequences that explore deeper service states.

Use cases

  • fuzz a rest api for security bugs
  • automatically test cloud service endpoints from an openapi spec
  • find crashes and reliability bugs in rest apis
  • generate stateful api request sequences for testing
  • regression testing for rest apis
  • check security properties of api endpoints

When to choose

  • you have an OpenAPI/Swagger specification for a REST API you want to test
  • you need automated discovery of security and reliability bugs in cloud services
  • you want stateful fuzzing that explores multi-request sequences
  • you need a research-backed fuzzing tool with multiple test generation strategies

When to avoid

  • your service has no OpenAPI specification available
  • you need to test GraphQL, gRPC, or non-REST interfaces
  • you want simple load or performance testing rather than bug finding
  • you need a GUI-driven manual API testing tool like Postman

Facets

cli-tool · maturity active

fuzzing testing security vulnerability-scanning http-client security testing apis developer-tools windows python cli rest-api openapi stateful-fuzzing api-testing microsoft-research linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
microsoft/restler-fuzzermain71

For agents

markdown · JSON · MCP: product_card(name="microsoft/restler-fuzzer")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem