‹ The Index

42crunch API Security Testing

plugin

Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language. Designed for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime te

Works with: Claude Code (native)
native: this artifact type is that client's own format

Category: Security — see all ranked ›

Work: Security review · Test automation

Who it is for: Security engineer · Software engineer

Install (Claude Code):

/plugin marketplace add anthropics/claude-plugins-community
/plugin install 42crunch-api-security-testing@claude-community

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

42crunch API Security Testing scores 47 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for 42crunch API Security Testing
[![tashan](https://tashan.sh/badge/plugin-42crunch-ai-claude-plugins-42crunch-api-security-testing.svg)](https://tashan.sh/capability/plugin-42crunch-ai-claude-plugins-42crunch-api-security-testing.html)

source ↗  ·  plugin:42crunch-ai/claude-plugins/42crunch-api-security-testing

Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.

Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.

Measured 2026-09-13  ·  scorer s5  ·  how  ·  something wrong here?