---
title: "OWASP Noir"
pageType: "tool-profile"
schemaVersion: "1.0"
snapshotId: "tv-20260915-f4c107995a2e"
generatedAt: "2026-09-15T07:02:20.000Z"
canonicalUrl: "http://toolvitals.com/tools/owasp-noir/"
jsonUrl: "http://toolvitals.com/api/agent/tools/owasp-noir"
indexable: true
---

# OWASP Noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

## Decision context

- Status: active
- ToolVitals score: 97/100
- Health score: 97/100
- Shipping score: 97/100
- Score mode: verdict
- Data confidence: 90/100
- Source coverage: 90/100
- Last evidence check: 2026-09-15

## Classification

- Use case: Security Scanning (security-scanning)
- Category: Security & Compliance (security)
- Tool mode: Source-visible project
- Openness: OSI-approved OSS
- License: MIT
- Tags: open-source, api-security, attack-surfaces, crystal-lang, devsecops, endpoints, hacktoberfest, owasp, owasp-noir, pentesting, security, shadow-api, api-first, crystal, attack-surface, endpoint-discovery

## Public repository signals

- Repository: [owasp-noir/noir](https://github.com/owasp-noir/noir)
- Stars: 1427 (adoption context only)
- Forks: 150
- Open issues: 10
- Last commit date: 2026-09-15
- Releases in 90 days: 4

## Source receipts

- [Official website](https://owasp-noir.github.io/noir/) — checked 2026-09-15
- [Source repository](https://github.com/owasp-noir/noir) — checked 2026-09-15

## Discovery status

- Search indexable: yes
- Reason: sufficient tool evidence

## Interpretation limits

- ToolVitals scores summarize bounded public maintenance, shipping, openness, and evidence signals. They are not user-review ratings.
- GitHub stars and related popularity metrics are adoption context, not quality evidence.
- Missing values mean not collected or not confidently established; they do not mean zero.
- Public signals do not prove security, uptime, support quality, customer satisfaction, or production suitability.
- Verify material decisions against the linked first-party sources and your own requirements.
