Replay pentests your web app on every QA pass now: injection flaws, broken access control, IDOR, the stuff AI-generated code tends to miss. Findings come back as full bug reports, evidence and suggested fix included. Schedule it daily or weekly and skip the "remember to test" step. You wake up to a queue of bugs already triaged. Same projects also test against dev, staging, prod, and localhost, so you're not maintaining separate QA setups per environment.
AI coding tools are good at making things that work. Security intuition is different, built from years of pentesting experience, and it's not something these models reliably apply yet. Agents write API endpoints that return the right data, not endpoints that check who's asking for it. That gap is where IDOR, broken access control, and injection flaws come from, and we kept seeing it in apps our own QA agents were testing.
So we built Security Scan into Replay QA. It runs a real pentesting pass against your live app, actual attack payloads, and turns findings into a report: the vulnerability, how it was triggered, what an attacker could do, and what to fix.
One catch: since it sends live attack traffic, the first run requires ownership verification. Non-negotiable, we're not running exploits against apps people don't control. Runs on the same schedule as the rest of Replay QA (every push, every PR, or a fixed cadence), so it's not something you have to remember to kick off.
Happy to answer questions all day and curious what you find if you point it at something you've shipped.
About Replay QA Security Scan on Product Hunt
“Automated Penetration Testing for AI-Built Apps”
Replay QA Security Scan launched on Product Hunt on September 8th, 2026 and earned 114 upvotes and 5 comments, placing #11 on the daily leaderboard. Replay pentests your web app on every QA pass now: injection flaws, broken access control, IDOR, the stuff AI-generated code tends to miss. Findings come back as full bug reports, evidence and suggested fix included. Schedule it daily or weekly and skip the "remember to test" step. You wake up to a queue of bugs already triaged. Same projects also test against dev, staging, prod, and localhost, so you're not maintaining separate QA setups per environment.
On the analytics side, Replay QA Security Scan competes within Developer Tools and Security — topics that collectively have 522.5k followers on Product Hunt. The dashboard above tracks how Replay QA Security Scan performed against the three products that launched closest to it on the same day.
Who hunted Replay QA Security Scan?
Replay QA Security Scan was hunted by fmerian. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Reviews
Replay QA Security Scan has received 1 review on Product Hunt with an average rating of 4.00/5. Read all reviews on Product Hunt.
For a complete overview of Replay QA Security Scan including community comment highlights and product details, visit the product overview.
Hey Product Hunt,
Kevin here from @Replay .
AI coding tools are good at making things that work. Security intuition is different, built from years of pentesting experience, and it's not something these models reliably apply yet. Agents write API endpoints that return the right data, not endpoints that check who's asking for it. That gap is where IDOR, broken access control, and injection flaws come from, and we kept seeing it in apps our own QA agents were testing.
So we built Security Scan into Replay QA. It runs a real pentesting pass against your live app, actual attack payloads, and turns findings into a report: the vulnerability, how it was triggered, what an attacker could do, and what to fix.
One catch: since it sends live attack traffic, the first run requires ownership verification. Non-negotiable, we're not running exploits against apps people don't control. Runs on the same schedule as the rest of Replay QA (every push, every PR, or a fixed cadence), so it's not something you have to remember to kick off.
Try it here: qa.replay.io
Happy to answer questions all day and curious what you find if you point it at something you've shipped.