Scan the app your users actually log into.
Mockingjay DAST crawls modern single-page apps behind SSO and MFA, tests every role, and validates each finding before it reaches your backlog. Run it on a schedule, or as a quality gate on every pull request.
- Single-page apps
- SSO, SAML & MFA
- Role-based testing
- CI/CD gates
- Validated findings
- Scheduled scans
- Authenticate, 100% completeSSO + MFA · 3 roles
- Crawl, 100% complete2,316 URLs · 184 forms
- Discover APIs, 100% complete212 XHR endpoints
- Active tests, 78% complete41,880 / 53,600 checks
- Validate, 30% completeRe-confirming 6 issues
- NewHighStored XSS in profile display name/settings/profile · role: userValidated
- NewMediumSession cookie missing SameSite attributeapp.example.com · all routesValidated
- NewMediumOpen redirect on logout/auth/logout?next=Validated
- FixedHighSQL injection in report filter/reports?sort=Retest passed
- FixedLowServer version disclosed in headersall responsesRetest passed
- OpenMediumCSRF on billing address update/billing/address · role: adminValidated
- Policy: block merge on new High or Critical
- Baseline: main @ 9f3c2a1
- Report: app.mockingjay.io/scans/4812
- Full scan
- Nightly · 02:00 SGT
- Incremental
- Every pull request
- Rate limit
- 20 req/s
Fewer false positives. More of the app covered.
Logs in like a real user
Record a login once, including SSO and MFA. Mockingjay keeps sessions alive and re-authenticates when they expire.
Understands modern front ends
A real browser engine renders React, Vue and Angular apps and discovers the API calls behind them.
Tests every role
Scan as a user, a manager and an admin, then compare what each can reach to surface access-control gaps.
Validated before reported
Each issue is re-confirmed with evidence before it’s raised, so engineers stop triaging noise.
Diffs against your baseline
See what’s new, fixed or unchanged since the last scan, and fail builds only on regressions.
Safe for shared environments
Rate limits, excluded paths and safe-check profiles keep scans from disrupting staging or production.
Catch it in review, not in production.
Add one step to your workflow. Mockingjay scans the preview environment, compares results against your main branch and only fails the build on new issues that cross your policy.
- GitHub Actions
- GitLab CI
- Azure Pipelines
- Jenkins
name: security
on: [pull_request]
jobs:
dast:
runs-on: ubuntu-latest
steps:
- uses: mockingjay/dast-action@v2
with:
target: ${{ env.PREVIEW_URL }}
profile: app-example-sso
fail-on: high
token: ${{ secrets.MJ_TOKEN }}Mapped to the OWASP Top 10.
- A01Broken access control
- A02Cryptographic failures
- A03Injection
- A04Insecure design
- A05Security misconfiguration
- A06Vulnerable components
- A07Authentication failures
- A08Integrity failures
- A09Logging and monitoring gaps
- A10Server-side request forgery
DAST questions
- How is this different from a pentest?
- DAST runs automatically and often, catching known vulnerability classes as code changes. A pentest adds human judgement for business logic and chained attacks. Most teams run both, and Mockingjay keeps their findings in one place.
- Can it scan production?
- Yes, with a safe-check profile, rate limits and excluded paths. Many teams scan a staging or preview environment on every change and production on a schedule.
- What do you need to set up authentication?
- A test account for each role and a recorded login. For SSO, we support SAML and OIDC flows, and TOTP-based MFA.
- How long does a scan take?
- Incremental pull request scans usually finish in minutes. Full scans depend on app size and usually take 2–6 hours.
See a scan of your own app.
We'll set up an authenticated profile with you and walk through the first results together.
