Releases: akha-security/akca
Release list
v0.2.5
Highlights
- Expand injection coverage with blind boolean LDAP and XPath checks, Velocity/Smarty/Razor SSTI probes, string-transform template evaluation, dynamic MSSQL timing payloads, Windows PowerShell/cmd variants, and stronger SQL boolean/arithmetic oracles.
- Add heuristic IDOR testing for single-profile scans while preserving strict multi-role BOLA ownership and anonymous-control proofs.
- Add route authorization-bypass coverage for encoded slashes, case normalization, method overrides, and safe-read fallback for non-GET endpoints.
- Extend SSRF coverage with IPv6, IPv4-mapped IPv6, hexadecimal/octal, zero-address, gopher and dict payloads.
- Add directory-listing discovery, broader cloud-takeover fingerprints, and cache parameter-cloaking verification.
Discovery and replay
- Preserve browser-captured XHR request templates ahead of synthetic forms, including original methods, bodies, headers, cookies, CSRF context and duplicate parameters.
- Add XML, multipart, raw GraphQL, WebSocket JSON, observed-header, cookie and positional path-identifier mutation surfaces.
- Discover common content roots and inferred parent directories from observed static assets, with structural Apache, nginx, Python and IIS directory-index detection.
- Auto-admit exact passive CDN dependencies learned from successful in-scope HTML/CSP without expanding active scan scope or forwarding credentials.
- Infer authorization role profiles from distinct configured authentication profiles and publish browser/OAST/identity/workflow/runtime readiness.
Verification and false-positive control
- Introduce SQL boolean-pair and numeric arithmetic-oracle proof types with alternating replay, clean controls and padding-aware semantic comparison.
- Publish per-target request, response, authentication/rate/gateway block, timeout, transport, proof-role and suppression diagnostics.
- Require current proof-policy evidence before a candidate can become a finding; unproven candidates fail closed and remain visible in coverage diagnostics.
- Distinguish browser-confirmed reflected XSS from true DOM-based XSS in terminal labels and stored evidence.
- Add end-to-end OAST self-testing, exact scan-scoped correlation and hidden health callbacks.
- Expand TLS, CSP, deserialization, LLM, sensitive-data and CVE validation while keeping evidence typed and replayable.
Reporting and operation
- Stream HTML, JSON, CSV, Markdown and SARIF findings with context cancellation instead of building large reports entirely in memory.
- Generate a bounded fast-partial report after Ctrl+C and allow a second interrupt to cancel reporting immediately.
- Preserve full Burp-style request/response evidence, add coverage diagnostics, and embed scanner version, commit and build date.
- Add machine-readable assurance profiles and a fail-closed complete-corpus release gate for module/capability omissions.
- Embed release build provenance and publish signed GitHub attestations in addition to SHA-256 checksums.
Validation
- Full Go package tests pass with
go test ./... -count=1. - Static analysis passes with
go vet ./.... - Strict observed-corpus benchmark quality retains 1.0 precision and an F1 score above 0.96.
- Regression coverage includes the six Burp Bounty SQLi surfaces, reflected-vs-DOM XSS classification, browser request replay, directory listing, OAST correlation, report streaming and interrupt behavior.
Install with Go
go install github.com/akha-security/akca/engine/cmd/akca@v0.2.5After the module proxy refreshes, @latest resolves to v0.2.5 as well:
go install github.com/akha-security/akca/engine/cmd/akca@latestDownloads
akca-windows-amd64.exe— Windows x64akca-linux-amd64— Linux x64akca-linux-arm64— Linux ARM64akca-darwin-amd64— macOS Intelakca-darwin-arm64— macOS Apple SiliconSHA256SUMS.txt— SHA-256 verification manifest
Release binaries include GitHub build-provenance attestations and can be verified with gh attestation verify <binary> -R akha-security/akca.
Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.
Full changelog: v0.2.4...v0.2.5
v0.2.4
Highlights
- Preserve complete captured HTTP requests and responses in findings and reports instead of shortening or rebuilding available raw evidence.
- Render structured-only evidence in a conventional Burp-style request/response format with standard headers, content length, and HTTP reason phrases.
- Ship a self-contained AKCA-branded HTML report with clearer vulnerability statistics, detailed finding sections, Request/Response/Both views, full-content controls, and print-safe evidence.
- Introduce a Lipgloss-based Scan Session panel with target emphasis, active status, request policy, engine, authentication, transport, OAST, and RAM information.
- Replace ETA with an elapsed timer and show readable vulnerability-module names with in-place Running-to-Completed updates.
- Make
-hconcise and--helpexhaustive, with usage examples limited to supported command forms. - Reduce normal terminal noise by aggregating browser dependency blocks and moving repetitive coverage diagnostics to verbose output without discarding coverage metadata.
Reliability fixes
- Preserve long response bodies, repeated headers, and trailing whitespace in generated evidence.
- Label transport-truncated and missing request/response evidence explicitly.
- Distinguish incomplete module coverage from execution failure so coverage gaps do not become misleading scanner errors.
- Improve browser dependency summaries and adaptive module accounting for failed, budget-limited, and unfinished targets.
Documentation
- Explain AKCA's context-aware, evidence-oriented scanning model and its relationship to established commercial DAST tools.
- Add an English workflow and security-testing capability catalog.
- Add Turkish and international community-support guidance. AKCA does not accept personal donations or sponsorships.
- Replace the previous README image with reproducible output captured from AKCA's local integration lab.
Validation
- Full Go package tests pass with
go test ./... -count=1. - Static analysis passes with
go vet ./.... - Report regressions cover raw transaction preservation, long bodies, escaping, missing and truncated evidence, tabs, full-content controls, print behavior, and clipboard paths.
- The Windows executable reports
AKCA ADVANCED WEB SECURITY SCANNER v0.2.4.
Downloads
akca-windows-amd64.exe— Windows x64akca-linux-amd64— Linux x64akca-linux-arm64— Linux ARM64akca-darwin-amd64— macOS Intelakca-darwin-arm64— macOS Apple SiliconSHA256SUMS.txt— SHA-256 verification manifest
Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.
Full changelog: v0.2.3...v0.2.4
v0.2.3
Fixed
- Present partial coverage prominently so an incomplete scan cannot be mistaken for complete assurance.
- Remove the standalone Coverage & Readiness section from HTML and Markdown reports while retaining machine-readable coverage metadata and the partial-scan warning.
- Replace raw CLI budget values and repetitive
unlimitedlabels with concise coverage and traffic descriptions. - Remove meaningless
0.0 req/soutput from the live progress row and format URL counts, memory values and status text consistently.
Added
- Add an executive HTML report overview with risk level, severity distribution, vulnerability statistics and detailed scan metadata.
- Organize findings into affected endpoint, description, impact, classification, recommendation and evidence sections.
- Add a transaction-focused request and response viewer with outbound/inbound context, method or status details, proof highlighting and copy controls.
- Rebuild the startup summary as a focused Scan Control dashboard for target, profile, discovery, verification and traffic policy.
- Document why Full Scan prioritizes application coverage and verified evidence over minimum completion time, including guidance for bounded scans.
Validation
- Full Go package tests pass with
go test ./... -count=1. - Static analysis passes with
go vet ./cmd/akca ./internal/report. - GitHub quality checks, race detection and the strict observed benchmark complete successfully.
- Windows executable was launched and verified to report
AKCA ADVANCED WEB SECURITY SCANNER v0.2.3.
Downloads
akca-windows-amd64.exe— Windows x64akca-linux-amd64— Linux x64akca-linux-arm64— Linux ARM64akca-darwin-amd64— macOS Intelakca-darwin-arm64— macOS Apple SiliconSHA256SUMS.txt— SHA-256 verification manifest
Browser-backed checks require Chrome, Chromium or Edge. Use AKCA only against systems you own or are explicitly authorized to test.
Full changelog: v0.2.2...v0.2.3
v0.2.2
Fixed
- Recursively analyze lazy-loaded JavaScript chunks and retain script dependencies independently from the API-finding confidence threshold.
- Preserve extra login fields, multi-stage authentication requests, cookies and response bearer tokens during automatic login and reauthentication.
- Require typed, replayable evidence for GraphQL, WebSocket, API exposure, JWT and authorization findings instead of promoting generic response differences.
- Reject SQL injection findings based on HTTP 400/422 responses or arithmetic behavior without replay and negative-control proof.
- Redact JavaScript secret values, nested login credentials, tokens and sensitive report fields by default.
Added
- Add browser-assisted crawling when direct HTTP requests are blocked, empty or receive browser-solvable responses such as HTTP 403.
- Add schema-derived, bounded GraphQL probes and typed disclosure checks without treating introspection or generic validation errors as vulnerabilities.
- Add authenticated multi-step login and bearer-token session support with refreshed credentials propagated into active scan profiles.
- Add coverage and module-readiness diagnostics to JSON, HTML and Markdown reports, including explicit partial-scan warnings.
- Add regression coverage for recursive SPA discovery, authenticated sessions, typed verification and report coverage behavior.
Validation
- Full Go package tests pass with
go test ./... -count=1 -timeout=180s. - Static analysis passes with
go vet ./.... - Controlled local testlab scan passes.
- Strict observed benchmark passes with precision, recall and specificity of
1.0and a false-positive rate of0on the available corpus. - Windows executable was launched and verified to report
AKCA ADVANCED WEB SECURITY SCANNER v0.2.2.
Downloads
akca-windows-amd64.exe— Windows x64akca-linux-amd64— Linux x64akca-linux-arm64— Linux ARM64akca-darwin-amd64— macOS Intelakca-darwin-arm64— macOS Apple SiliconSHA256SUMS.txt— SHA-256 verification manifest
Use AKCA only against systems you own or are explicitly authorized to test.
Full changelog: v0.2.1...v0.2.2
v0.2.1
Fixed
- Reject SQL injection evidence when baseline or payload responses return HTTP 4xx, preventing bad-request boolean probes such as
1 AND 20909=20909from being reported as confirmed injection. - Continue crawler discovery through browser-assisted rendering when initial HTTP requests are blocked or empty, including 403 responses that still load in a normal browser.
- Remove crawler route-saturation caps from unbounded full scans and fix queue-drain accounting so discovery does not end while requests are still being scheduled.
- Initialize adaptive module budgets from the module catalog so every registered full-scan module receives a request plan and usage counter.
Added
- Coverage-gap reporting for blocked or contentless crawl starts, making
0 crawler requestsstyle failures visible instead of silently completing. - Regression tests for blocked-browser crawling, redirect discovery, SQLi 4xx false-positive rejection and catalog-wide module budget initialization.
Validation
- Full Go package tests pass with
go test ./... -count=1. - Static analysis passes with
go vet ./....
v0.2.0
v0.1.9
v0.1.9
Fixed
- Reduce false positives in CORS, open redirects, CSTI, JSONP, WebSocket, prototype pollution, parser differential and route authentication checks by requiring evidence of the claimed security effect.
- Validate actual redirect destinations instead of attacker URLs embedded in nested query parameters.
- Repair stored-XSS tracking and raw HTTP smuggling verification; preserve raw request and response evidence.
- Include response status and security-relevant headers in finding replay comparisons.
- Correct coverage accounting, persistent learning outcome counts, response similarity and cache-hit detection.
- Share request budgets across HTTP, browser HTTP and raw protocol probe paths.
- Restore Copy Response, Copy Request and Copy cURL in HTML reports, including a clipboard fallback.
- Isolate the CLI integration test from the user's data directory.
Added
- Private-canary proof policies and browser cross-origin read observations.
- Regression tests for the reported false positives, raw protocol replay, clipboard behavior and shared budgets.
- Audit and validation reports documenting remaining verification limits.
Validation
- The preceding changes passed tests in 80 Go packages and
go vet. - The strict observed benchmark passed for the existing corpus.
- Live third-party/browser coverage is not inferred from fixture tests; local race testing required an unavailable GCC toolchain.
v0.1.8
v0.1.8
Added
- Physical wire transport interception with strict request budgets across redirects, retries and per-host pacing.
- Timing-based blind NoSQL verification with baseline calibration, zero-delay controls and delayed confirmation.
- Native multipart and XML request mutation, including boundary management and crawler form encoding support.
- Live health metrics, improved scan comparison streaming and collision-resistant scan IDs.
Fixed
- Expand SQL error detection and tolerate valid timing findings with expected server error responses.
- Bound crawler route saturation and restrict automatic redirect scope adoption to canonical host pairs by default.
- Correct reflection sentinel probes and dynamic payload assembly.
- Harden report-builder error handling and persist scan records before session start.
v0.1.7
v0.1.7
Added
- GET-to-POST method pivoting with dual query/body hidden-parameter discovery.
- Automatic promotion of confirmed hidden POST parameters into scanner targets.
- Surface-adaptive module budgeting with per-category probe quotas and starvation isolation.
- Expanded high-impact parameter wordlists with context-aware prioritization for admin, cloud, upload and proxy routes.
Fixed
- Preserve final scan status and avoid health-metrics nil pointer panics.
- Count request budgets outside retry loops and preserve HTTP 429 evidence with
Retry-Afterhandling. - Use cryptographic randomness for WAF bypass headers and correct rate-limiter jitter.
- Tighten preflight, scope expansion, non-standard port handling, proxy port allocation and UTF-8 truncation behavior.
Optimized
- Scope TLS misconfiguration checks to root hosts.
- Reduce noisy coverage notices in normal CLI output.
- Run
api_versioningonce per host on root or base API endpoints.
v0.1.6
v0.1.6
Added
- Type-aware probing across SQL injection, command injection, NoSQL injection, IDOR/BOLA and path traversal modules.
- Numeric-safe SQL and command probes for parameters that reject free-form payload prefixes.
- Nested dotted-path support for MongoDB operator queries and authentication bypass bodies.
- Category-weighted request budgets with rollover from completed modules and groups.
- Coverage-gap metrics when configured budgets prevent full target coverage.
Fixed
- Support bracket, dot and unindexed array JSON mutations without overwriting container values.
- Target only scalar JSON leaf values to avoid schema-validation rejections.
- Balance Windows and Linux traversal testing to avoid premature fast-fail behavior.