Buğra Cem B.
BB
Buğra Cem B.
Sistem Güvenliği Uzman Yardımcısı
Small-Business (50 or fewer emp.)
"API Security Scanner"
5/5
What do you like best about apisec.ai?

As a programmer and student who is learning about cyber security ı am really eager to learn and use this program for 2 reasons firstly ı know that application interface is really important topic in fields of software programming and cyber security and because of this reason i need to be sure about the apis that ı developed are secure .This tool give me this chance.And secondly it is a free tool.They give you a free service which is developed for your usage and you can accomplish your goals on thses fields. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

I could not see any disadvantages for now but if there is anything like an issue about the program or other things ı think that the owners of this application can solve it and provide you a good service so ı suggest you to give a chance to this application. Review collected by and hosted on G2.com.

Saif Eddine L.
SL
Saif Eddine L.
Consultant intern
Small-Business (50 or fewer emp.)
"Effortless API Protection with apisec.ai"
4/5
What do you like best about apisec.ai?

What I like best about apisec.ai is its ability to automate comprehensive security testing across all our APIs with minimal configuration. The platform integrates seamlessly into our CI/CD pipeline, enabling continuous API security validation without slowing down development. I also appreciate the intuitive UI, which makes it easy to visualize threats, and the intelligent engine that uncovers vulnerabilities that traditional scanners often miss. It's truly a set-it-and-forget-it solution that gives peace of mind. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

While apisec.ai offers powerful automation and deep security insights, one area for improvement is the initial learning curve when setting up complex environments or custom test cases. Some advanced configurations require a bit more documentation or support to fully utilize the platform's capabilities. Additionally, while the UI is clean, occasional lag or loading delays in the dashboard can slow down the workflow slightly. That said, their support team is responsive and continually rolling out updates, which shows their commitment to improvement Review collected by and hosted on G2.com.

Syed Mohammad Irtiza R.
SR
Syed Mohammad Irtiza R.
Contributor
Small-Business (50 or fewer emp.)
"The Ease to master API testing"
4.5/5
What do you like best about apisec.ai?

APIsec.ai stands out for its automated and continuous API security testing, which proactively detects vulnerabilities before they can be exploited. It seamlessly integrates into development workflows, allowing teams to secure their APIs without slowing down innovation. The platform covers a wide range of security concerns, including OWASP API Security Top 10, business logic flaws, and access control issues. Its user-friendly interface simplifies configuration and integrates smoothly with CI/CD pipelines. Additionally, APIsec University offers free courses and fosters a strong security community, contributing to the broader advancement of API security knowledge. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

While APIsec.ai’s comprehensive automation is a strength, it can also present a steep learning curve for teams that are new to advanced API security, sometimes making the initial setup feel overly complex. Additionally, its extensive testing features may occasionally result in false positives that require further manual review. These factors might slow down the initial adoption process for organizations not already versed in robust security practices. Review collected by and hosted on G2.com.

MK
Mayur K.
Associate Consultant
Mid-Market (51-1000 emp.)
"An In-Depth Analysis of API Security Protocols and Vulnerabilities"
5/5
What do you like best about apisec.ai?

What I like best about APIsec.ai is its automation-first approach to API security testing. It eliminates the traditionally manual and time-consuming aspects of API penetration testing by offering continuous, automated testing that seamlessly integrates with CI/CD pipelines. This enables organizations to identify and remediate vulnerabilities early in the development lifecycle.

Additionally, APIsec.ai’s ability to generate attack simulations based on real API traffic and OpenAPI specs makes the testing both dynamic and highly relevant. It doesn’t just look for generic OWASP Top 10 issues, but tailors its testing to the unique logic and structure of the API being analyzed.

Its user-friendly interface, detailed reporting, and ease of integration with modern DevSecOps workflows also contribute to making it a standout platform in the API security landscape. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

integration with certain third-party tools or dashboards might require additional configuration or customization, depending on the organization’s ecosystem. Review collected by and hosted on G2.com.

Mohammad K.
MK
Mohammad K.
Information Security Consultant
Mid-Market (51-1000 emp.)
"A Solid Start for a New API Security Tool"
5/5
What do you like best about apisec.ai?

seamlessly integrates with CI/CD pipelines, allowing for continuous, hands-free security assessments without disrupting development workflows.

The most helpful aspect is its intelligent vulnerability detection and prioritization. ApiSec.ai doesn’t just report issues — it highlights the most critical vulnerabilities, helping teams focus their remediation efforts efficiently. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

One downside is the learning curve for new users. The initial setup and understanding of test case customization can be a bit complex, especially for teams without prior experience in API security tools.

What is least helpful is the limited documentation in certain areas. Some advanced features lack in-depth guidance or real-world usage examples, which can slow down adoption and onboarding.

Other potential downsides include: Review collected by and hosted on G2.com.

OS
OUMA S.
Information Security Assurance Analyst
Mid-Market (51-1000 emp.)
"Testing API Vulnerabilies in crAPI"
5/5
What do you like best about apisec.ai?

What i like best about apisec.ia is its ability to carryout quick detailed scan of an API endpoint using OWASP Top 10 Checklist and ability to quantify vulnerability according to CVSS rating and generate detailed scans report for analysis which increases efficiency interms of analyzing many API endpoints in a short time. Additionally I like about apisec.ai is ease of use forexample dashboards with graphs, also ease of implementation and ease of integration during setup. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

The downsides of using apisec.ai is that sometimes using automated api scan tools may flag vulnerabilities as present in an api yet they are false positives. Also what i dont like about automated api scan tools like apisec.ai is that it takes away the aspect of human manual analysis which sometimes help to uncover some vulnerabilities that are not easily found by apisec.ai in an API endpoint Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"Practical training, rich in content and straight to the point about API security"
5/5
What do you like best about apisec.ai?

The practical approach, with real simulations using crAPI and tools like Burp Suite and jwt_tool, is excellent for learning by applying. The teaching method is clear, the videos are short and to the point, and the quizzes help to effectively reinforce the content.

The focus on the OWASP API Security Top 10, combined with practical exercises, allows for an understanding in practice of how each vulnerability can be exploited and how to protect oneself. Additionally, the use of real tools from the daily life of a security analyst (ZAP, Postman, Burp, JWT_Tool) prepares the student to truly engage.

Advantages such as delivering updated content focused on the real world enable us to get hands-on with environments like vAPI and crAPI and offer consistent didactic material and quizzes that consolidate learning. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

Some modules could explore a bit more the defensive side (mitigation and protection in production environments), in addition to providing recommendations focused on secure architecture and hardening practices with more in-depth examples.

Some lessons only point to other tools without delving into their use. For example, it would be interesting to have videos demonstrating step-by-step use of each tool, especially for those who are just starting.

Disadvantages:

The absence of subtitles in Portuguese may hinder access for some professionals in the field in Brazil;

There could be a progress panel by vulnerability (e.g., "completed: BOLA, remaining: SSRF") for better tracking;

The "Beyond the Top 10" section is useful but still not explored in depth. Review collected by and hosted on G2.com.

SA
Shamsudeen A.
Information Security Analyst
Small-Business (50 or fewer emp.)
"APISEC.AI REVIEW BY SHAMSUDEEN AJAKA"
5/5
What do you like best about apisec.ai?

Apisec.ai is an advanced API security testing platform that automates the discovery of vulnerabilities by generating and executing thousands of test cases based on API specifications like Swagger or OpenAPI. It seamlessly integrates into CI/CD pipelines, enabling shift-left security practices and continuous testing. The platform provides deep coverage of threats, including those in the OWASP API Top 10, with comprehensive reports and remediation guidance. Its ability to test without manual scripting makes it highly efficient for securing APIs in development and production. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

While apisec.ai offers powerful automated API security testing, it has some limitations, such as a learning curve for new users, dependence on well-documented API specifications, and limited flexibility for nuanced manual testing scenarios. Additionally, its pricing may not be suitable for smaller teams or startups, and like many automated tools, it can occasionally produce false positives or miss subtle issues. Despite these drawbacks, it remains a valuable solution when paired with manual testing and proper API documentation practices. Review collected by and hosted on G2.com.

RY
Rohit Y.
Security Analyst
Mid-Market (51-1000 emp.)
"Comprehensive API Security Made Simple"
5/5
What do you like best about apisec.ai?

What I like best about apisec.ai is its ability to automate comprehensive API security testing without slowing down the development cycle. The platform seamlessly integrates into our CI/CD pipeline and continuously scans for vulnerabilities, including business logic flaws—which are often missed by traditional tools. I also appreciate how intuitive the interface is; even team members without deep security backgrounds can understand the results and take action. The detailed reporting, combined with actionable remediation steps, makes it much easier to address issues early in the development process. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

While apisec.ai is a powerful platform, there are a few areas where it could improve. The initial setup and configuration, especially for complex environments or custom APIs, can be a bit time-consuming and may require support from their team. Additionally, while the UI is generally user-friendly, some of the advanced features could benefit from more in-app guidance or tooltips to help new users make the most of them. Lastly, integration with certain CI/CD tools could be more seamless—but their support team is responsive and helpful in resolving any issues. Review collected by and hosted on G2.com.

Alkaid P.
AP
Alkaid P.
Software Engineer
Mid-Market (51-1000 emp.)
"ApiSec is wonderful!!"
5/5
What do you like best about apisec.ai?

The most helpful or the best thing about apisec.ai is that I am able to find vulnerabilities in our application that I cant be able to see in doing it manually. Basically the automation itself is great! and I love that I am also able to download a report of the vulnerabilities itself and just present it right away! The ease of integration has been very easy too and customer support was also there since they taught me everything before making use of it. Review collected by and hosted on G2.com.

What do you dislike about apisec.ai?

One thing that I would recommend is maybe add a better error handling, for example some users might not understand what to put on the Open API and would have trouble understanding it. Review collected by and hosted on G2.com.