Highlights
- Expand injection coverage with blind boolean LDAP and XPath checks, Velocity/Smarty/Razor SSTI probes, string-transform template evaluation, dynamic MSSQL timing payloads, Windows PowerShell/cmd variants, and stronger SQL boolean/arithmetic oracles.
- Add heuristic IDOR testing for single-profile scans while preserving strict multi-role BOLA ownership and anonymous-control proofs.
- Add route authorization-bypass coverage for encoded slashes, case normalization, method overrides, and safe-read fallback for non-GET endpoints.
- Extend SSRF coverage with IPv6, IPv4-mapped IPv6, hexadecimal/octal, zero-address, gopher and dict payloads.
- Add directory-listing discovery, broader cloud-takeover fingerprints, and cache parameter-cloaking verification.
Discovery and replay
- Preserve browser-captured XHR request templates ahead of synthetic forms, including original methods, bodies, headers, cookies, CSRF context and duplicate parameters.
- Add XML, multipart, raw GraphQL, WebSocket JSON, observed-header, cookie and positional path-identifier mutation surfaces.
- Discover common content roots and inferred parent directories from observed static assets, with structural Apache, nginx, Python and IIS directory-index detection.
- Auto-admit exact passive CDN dependencies learned from successful in-scope HTML/CSP without expanding active scan scope or forwarding credentials.
- Infer authorization role profiles from distinct configured authentication profiles and publish browser/OAST/identity/workflow/runtime readiness.
Verification and false-positive control
- Introduce SQL boolean-pair and numeric arithmetic-oracle proof types with alternating replay, clean controls and padding-aware semantic comparison.
- Publish per-target request, response, authentication/rate/gateway block, timeout, transport, proof-role and suppression diagnostics.
- Require current proof-policy evidence before a candidate can become a finding; unproven candidates fail closed and remain visible in coverage diagnostics.
- Distinguish browser-confirmed reflected XSS from true DOM-based XSS in terminal labels and stored evidence.
- Add end-to-end OAST self-testing, exact scan-scoped correlation and hidden health callbacks.
- Expand TLS, CSP, deserialization, LLM, sensitive-data and CVE validation while keeping evidence typed and replayable.
Reporting and operation
- Stream HTML, JSON, CSV, Markdown and SARIF findings with context cancellation instead of building large reports entirely in memory.
- Generate a bounded fast-partial report after Ctrl+C and allow a second interrupt to cancel reporting immediately.
- Preserve full Burp-style request/response evidence, add coverage diagnostics, and embed scanner version, commit and build date.
- Add machine-readable assurance profiles and a fail-closed complete-corpus release gate for module/capability omissions.
- Embed release build provenance and publish signed GitHub attestations in addition to SHA-256 checksums.
Validation
- Full Go package tests pass with
go test ./... -count=1. - Static analysis passes with
go vet ./.... - Strict observed-corpus benchmark quality retains 1.0 precision and an F1 score above 0.96.
- Regression coverage includes the six Burp Bounty SQLi surfaces, reflected-vs-DOM XSS classification, browser request replay, directory listing, OAST correlation, report streaming and interrupt behavior.
Install with Go
go install github.com/akha-security/akca/engine/cmd/akca@v0.2.5After the module proxy refreshes, @latest resolves to v0.2.5 as well:
go install github.com/akha-security/akca/engine/cmd/akca@latestDownloads
akca-windows-amd64.exe— Windows x64akca-linux-amd64— Linux x64akca-linux-arm64— Linux ARM64akca-darwin-amd64— macOS Intelakca-darwin-arm64— macOS Apple SiliconSHA256SUMS.txt— SHA-256 verification manifest
Release binaries include GitHub build-provenance attestations and can be verified with gh attestation verify <binary> -R akha-security/akca.
Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.
Full changelog: v0.2.4...v0.2.5