RESTler
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
What RESTler is
RESTler is a stateful REST API fuzzing tool from Microsoft Research for testing cloud services and finding security and reliability bugs. It reads an OpenAPI (Swagger) specification and infers producer-consumer dependencies between request types. Testing runs in four modes: compile, test, fuzz-lean and fuzz. Compile mode generates a RESTler grammar from an OpenAPI JSON or YAML definition. Test mode acts as a smoke test and reports specification coverage. Any response with status 500 is reported as a bug. Checkers send targeted request sequences to find logic bugs such as resource leaks. Found bugs are grouped into buckets with replay logs. It runs on 64-bit Windows and Linux, with experimental macOS support.
Written from the project's README, read .
- Category
- Security testing, API testing
- License
- MIT
- Language
- Python
- Changelog
- Releases on GitHub
Repository metrics
Status
slowLast commit 91 to 365 days before the fetch date.Computed from the last commit date and the archive flag on the fetch date. See the status rules.
Alternatives
Listed security testing tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from RESTler's, with its source.
sqlmap: Scan targets: Web application parameters: GET, POST, cookie, User-Agent and Referer values. source: Docs: Features
garak: Scan targets: LLMs and dialog systems reached through generators. source: README
Bandit: Scan targets: Python code, for common security issues. source: README
OWASP Nettacker: Scan targets: IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP/HTTPS URLs. source: README
Atheris: Scan targets: Python code and native extensions written for CPython. source: README
Trivy: Scan targets: Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes. source: README
Nuclei: Scan targets: Target URLs and hosts, from a single target or a list file. source: README
Gitleaks: Scan targets: Secrets such as passwords, API keys and tokens in git repositories, files and stdin. source: README
Questions
Is RESTler open source?
Yes. RESTler is released under MIT, an OSI-approved license, as reported by the GitHub API on 2026-09-22.
Is RESTler maintained?
On 2026-09-22, the last commit to the default branch was on 2026-02-13, so the listed status is slow. Rule: Last commit 91 to 365 days before the fetch date.
How many GitHub stars does RESTler have?
2,946 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.
What language is RESTler written in?
The repository's primary language, as reported by the GitHub API, is Python.
Sources
- GitHub REST API: repository, read
- GitHub REST API: commits, read
- GitHub REST API: tags, read
- GitHub REST API: contributors, read
- README, read