← Back to tools
Security extensions / PROJECT OVERVIEW

Caido extensions

Purpose-built extensions for access-control testing, request workflows, and deeper application analysis.

Caidoweb securityextensions

The idea

A testing proxy becomes more useful when it fits the way you investigate applications. This collection of proprietary Caido extensions supports focused testing and analysis workflows.

Areas of focus

  • IDOR and BOLA testing workflows.
  • Programmable request mutation and replay.
  • GraphQL security testing.
  • JavaScript and abstract syntax tree analysis.
  • Endpoint discovery.
  • Out-of-band application security testing workflows.

Small tools, specific questions

Each extension addresses part of the research process: understanding the application’s surface, organizing request experiments, or following behavior that is not visible in an immediate HTTP response.

Keeping these capabilities close to the testing workflow helps reduce repetitive work and leaves more room for manual investigation.

Project notes

These extensions are proprietary. This page introduces their scope; it does not offer a public release. Future articles can explore individual design decisions and workflows without exposing private implementation details.

Built by rollin.All tools

Search posts

Articles, CTF writeups, and notes. Press Esc to close.