AppSecNews
DAST Not recorded Growing

Caido

by Caido Labs

Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.

Visit caido.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Caido in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • License: the batch record says unknown. The product has both a free and a paid edition, confirm the exact licensing terms with the vendor
  • Feature set moves quickly, confirm which capabilities are current before publishing
  • Integration list left empty deliberately: confirm whether any are current

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Caido is an intercepting proxy for web application testing. Traffic from a browser or client routes through it, every request and response is stored, and you can view, edit, replay and forward anything in the stream. Around that core sit the tools a tester expects: a replay workspace for iterating on a single request, an automation workspace for driving payload lists across chosen insertion points, a match and replace layer for rewriting traffic in flight, and a sitemap view of what has been observed.

Two design decisions set it apart. The first is the split between a server component that does the proxying and storage and a client that connects to it, which means you can run the server on a remote host, a cloud instance or a jump box and drive it from a local desktop or browser client without shuttling data around. The second is a query language for traffic filtering, so narrowing a large capture is a written expression against fields rather than a set of checkbox filters. A plugin system supports extending the tool, and a command line component allows scripted use.

Where it fits

This is a human driven tool on a tester's machine or on infrastructure a tester controls. It suits penetration testing, bug bounty work and hands on verification of specific findings. It is not a scheduled scanner and it does not produce an unattended assessment of an estate. As with any proxy, its value depends entirely on the operator knowing what to look for.

Strengths

  • Remote server plus local client architecture is genuinely useful for testing from a cloud host or keeping long running captures off a laptop.
  • The traffic query language makes finding one request in a large capture fast.
  • Modern interface and responsive performance, which is a real quality of life difference during long testing sessions.
  • Plugin system and scripting support for target specific automation.

Limitations

  • Younger than the established proxies, so the extension ecosystem and the volume of community knowledge are much smaller.
  • Automated scanning capability is limited compared with tools that ship a mature active scanner, so this is a manual testing instrument.
  • Licensing and edition boundaries should be checked directly, since the catalog record for this entry is incomplete.

Who it suits

A strong option for individual testers and bug bounty hunters who want a fast, modern proxy and are comfortable being early to a growing tool. Less suitable for a team that needs a mature scanner, enterprise reporting or a large library of existing extensions to lean on.

Used Caido? Recommend it under your own name and title.

Recommend this tool