Skip to content
Innovation & Growth

Free OWASP tool lists routes in code, including undocumented ones

Noir reads source code across 205 frameworks. The project says its list gives scanners paths crawling would miss.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Free OWASP tool lists routes in code, including undocumented ones

Photo: Simon Petereit / Pexels

Key finding

Frameworks covered: 205 (Source: OWASP Noir project page (GitHub), cited by Help Net Security, September 30, 2026)

A test covers only the routes someone knew to list

Security testing has a blind spot that is easy to overlook. A route can exist in an application's code, stay out of the documentation, and still respond to anyone who discovers its address. A test plan built from the documentation will skip it.

OWASP Noir, a free open-source project, targets that gap. The argument behind it, and the one made here, is that securing software starts with a plain inventory of what the software responds to. That is a view about priorities. The tool does not prove it.

What Noir produces

OWASP describes Noir as a static analysis tool. Static means it examines code without running the application. From the code it pulls out paths, methods, parameters, headers and cookies, plus the source files behind them. Help Net Security adds that an entry can be traced to an exact line of code.

Shadow APIs appear in the same list. These are endpoints that exist in the code but were never written into documentation. Deprecated routes and undocumented handlers show up there too. Noir has no special mode for them.

205
Frameworks covered
Source: OWASP Noir project page (GitHub), cited by Help Net Security, September 30, 2026

How reading code finds routes

Web frameworks tend to declare routes in recognizable ways. Noir's static rules are written around those habits. Help Net Security says no per-language setup or plugins are needed. Noir works out what the project is written in and how it wires up its routes, then records each route it finds.

Static rules do not apply in two cases, and that is where Noir falls back to a model. One is a framework the rules do not cover. The other is an application that uses one-off custom routing.

In those cases Noir can pass the code to a language model through providers such as OpenAI or Ollama. Help Net Security advises a manual check of routes that come back this way, because a model's output is not fixed by a rule.

Why crawling leaves gaps

Dynamic scanners such as ZAP and Burp Suite test a running application from outside. Help Net Security says they find many routes by crawling, which means following links. A route that no link leads to can go untested.

The Noir project says its route list gives these tools paths they would not have reached by crawling. Noir can act as a proxy target for ZAP, Burp Suite, Caido and Gori. It can also export an OpenAPI file, a standard description of an API, for them to import.

The two methods answer different questions. Crawling shows what a visitor can reach. Reading code shows what the application contains. Each can miss ground the other covers.

One list, three readers

The maintainers say Noir began as an aid for testing. They now describe the same list as serving human reviewers, AI code auditors and scanners.

Help Net Security reports that Noir has 17 built-in labels, called taggers. A label can single out endpoints that handle payments or administration. A reviewer can then read those first instead of working through the whole repository.

For AI reviewers, an --ai-context option bundles extra material with each endpoint. That includes the surrounding checks, risky operations and signals. Per the reporting, a model can then read one handler at a time.

The lesson for leaders is practical. An AI code reviewer is only as useful as what it is pointed at. A list of entry points gives it somewhere to start.

29
Languages covered from one binary
Source: Help Net Security, September 30, 2026

Where to be careful

The sources give no accuracy figures for Noir. The maintainers say they test static-rule accuracy against fixtures for each framework. That describes their method. It is not a published result.

Noir also does not scan running systems. It reports what the code declares. It is one input to testing, not a verdict on whether a route can be exploited.

22
Output formats supported
Source: Help Net Security, September 30, 2026

Questions to put to your security team

Ask where your list of endpoints comes from. A list taken from documentation can miss routes that exist only in code. A list taken from crawling can miss routes the crawler does not reach.

Ask whether your dynamic scanner receives a route list from source code or has to find routes itself. Ask who owns each undocumented route once it is found, and who decides whether it is retired or documented.

If your team uses AI to review code, ask what context the model receives. Ask who checks any route that came from a language model rather than from fixed rules.

Noir is free on GitHub, so trying it costs little. Whatever tool you use, a test covers only the doors someone knew to list.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: OWASP (Open Web Application Security Project).

Share this insight