Escape - The API Security Blog
Get a demo
  • Escape Platform
  • Case studies
  • Best Practices
  • Events
  • Community
Get a demo
Tagged

GraphQL

A collection of 28 posts

Pentesting GraphQL 101 
Part 1 - Discovery
Pentesting

Pentesting GraphQL 101 Part 1 - Discovery

Recent statistics say that you have queried at least one GraphQL endpoint today. For me, as a Penetration tester, it is just a matter of concern, especially since high-quality Pentesting guides/articles are scarce online, which only signals that GraphQL security is still rudimentary. So I decided to start this

  • Karim Rustom
Karim Rustom Jul 19, 2022 • 6 min read
Introducing GraphMan: instantly scaffold a Postman collection for your GraphQL API
Announcement

Introducing GraphMan: instantly scaffold a Postman collection for your GraphQL API

While querying, developing, and testing your GraphQL APIs with postman is easy and convenient, it has a big caveat: if you want to cover an endpoint with all its queries and mutations entirely, it will take you hours and repetitive steps to create every request, and you'll almost

  • Nohé Hinniger-Foray
Nohé Hinniger-Foray Jul 11, 2022 • 3 min read
9 GraphQL Security Best Practices
AppSec

9 GraphQL Security Best Practices

GraphQL has no security by default. All doors are open for the most basic attacks. Read more to learn about the exact threats and some simple strategies you can implement to get your users' data under lock and key 🔐

  • Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou Mar 11, 2022 • 8 min read
Escape - The API Security Blog © 2025
  • Get a demo
  • Escape's proprietary business logic algorithm
  • Escape vs Invicti
  • Top DAST tools 2025
  • Case Studies
  • Learn how to test your GraphQL APIs
  • gRPC API Security
  • Top Qualys Alternative: Escape vs Qualys DAST
  • GraphQL Security
  • Escape vs Noname Security
  • GraphQL Armor
  • Escape Community
  • About Us
  • Privacy Policy
  • API Security Academy
  • API Gateway Security Best Practices
  • Top API security tools