DongTai IAST
Score6.9
Rank#4 of 14
PriceFree
Free planYes
Runs onAPI, Linux, Self-hosted, Web
Summary
DongTai IAST is ranked #4 of 14 in interactive application security testing software on Everything Xiaomi. It runs on API, Linux, Self-hosted, Web. There is a free plan.
DongTai IAST plans and pricing
All plansOpen-source self-hosted deployment Free Docker Compose single-node or Kubernetes cluster deployment github.com · 4 Oct 2026
Compared on interactive application security testing software
Facts
- Product
- DongTai IAST is an open-source interactive application security testing tool that uses passive instrumentation to detect common vulnerabilities in Java applications and third-party components in real time.github.com · 3 Oct 2026
- Analysis
- The project describes its engine as analyzing HTTP, HTTPS, and RPC requests using method-call data and taint tracking.github.com · 3 Oct 2026
- Detection languages
- The documentation lists Java, Python, PHP, and Go as supported detection languages.docs.dongtai.io · 3 Oct 2026
- Vulnerability workflow
- The overview says DongTai analyzes runtime application data flows, prioritizes verified vulnerabilities by risk, and helps developers fix code in real time.docs.dongtai.io · 3 Oct 2026
- Server capabilities
- The server provides a user management interface, vulnerability analysis and reports, vulnerability notifications, Web API, project management, and custom vulnerability rules.docs.dongtai.io · 3 Oct 2026
- IDE integration
- The project describes an IntelliJ IDEA plugin that can run the Java probe and detect vulnerabilities inside the IDE.github.com · 3 Oct 2026
- Use cases
- The project lists DevSecOps vulnerability detection, open-source vulnerability research, and security testing before release as use cases.github.com · 3 Oct 2026
- IAST method
- The documentation identifies DongTai as passive IAST, using application test traffic to analyze vulnerabilities without running dedicated attack tests.docs.dongtai.io · 3 Oct 2026
- Agent status
- The agent guide marks Python, PHP, and Go agents as beta and says community-maintained beta agents are not guaranteed to deploy successfully.docs.dongtai.io · 3 Oct 2026
- Runtime services
- The project says its base image includes MySQL and Redis services.github.com · 3 Oct 2026
- License
- The repository lists an Apache-2.0 license.github.com · 3 Oct 2026
- Support
- The project directs users with questions to its GitHub Discussions forum.github.com · 3 Oct 2026
- Collection and reporting
- Its agent monitors and collects web application traffic data, sends it to DongTai Server for analysis, and the server reports identified vulnerabilities with full reports available in the management server.docs.dongtai.io · 4 Oct 2026
- Supported languages
- The documentation lists Java, Python, PHP, and Go as supported detection languages.docs.dongtai.io · 4 Oct 2026
- Deployment options
- DongTai offers SaaS service and localized deployment, with Docker and Kubernetes deployment options.github.com · 4 Oct 2026
- Detection features
- The product site lists application vulnerability testing, open-source component vulnerability detection, sensitive information detection, and hardcoded information detection.dongtai.io · 4 Oct 2026
- Finding analysis
- The product site says it provides automated vulnerability verification and tracing, with detailed vulnerability analysis and location.dongtai.io · 4 Oct 2026
- API and DevSecOps
- The product site says API support enables integration into DevSecOps workflows.dongtai.io · 4 Oct 2026
- Development use
- The project describes use in development pipeline testing, open-source software vulnerability discovery, and security testing before release.github.com · 4 Oct 2026
- Security policy
- The GitHub security policy lists versions 1.8.5 and later as supported for security updates.github.com · 4 Oct 2026
- Commercial deployment requirements
- The commercial deployment guide says the user running iastctl needs sudo privileges and notes incompatibility for versions below 1.13.0 unless upgraded manually.doc.dongtai.io · 4 Oct 2026
- Support and community
- The project README directs questions to DongTai Discussions and welcomes code contributions.github.com · 4 Oct 2026
Best DongTai IAST alternatives
See all 12Where it ranks on Everything Xiaomi
Is DongTai IAST yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/HXSecurity/DongTai· checked 3 Oct 2026
- docs.dongtai.io/docs/introduction/· checked 3 Oct 2026
- docs.dongtai.io/docs/introduction/architecture/· checked 3 Oct 2026
- docs.dongtai.io/docs/introduction/iast/· checked 3 Oct 2026
- docs.dongtai.io/docs/category/agent-%E5%AE%89%E8%A3%85%· checked 3 Oct 2026
- docs.dongtai.io/docs/introduction/dongtai/· checked 4 Oct 2026
- github.com/HXSecurity/DongTai/blob/develop/README.· checked 4 Oct 2026
- dongtai.io· checked 4 Oct 2026
- github.com/HXSecurity/DongTai/security· checked 4 Oct 2026
- doc.dongtai.io/docs/getting-started/start-shangye/· checked 4 Oct 2026




