Skip to main content
Resources · Product Updates

What's new

New capabilities and meaningful improvements, explained in terms of what changes for your team. For version-by-version detail, see the release notes.

Updates
6
Current version
5.2.14
Latest update
February 12, 2026
Detail
See release notes

All updates

Newest first

Versions and dates track the published package on PyPI, so this page and the version in your requirements file never describe different software.

v5.2

February 12, 2026

Detection

Business logic testing, as a first-class scan type

Twenty-nine abuse patterns (race conditions, IDOR, price manipulation, workflow bypass) now run as their own scan phase, against the class of flaw that has no CVE and no signature.

  • 29 business logic abuse patterns
  • Race condition detection with controlled concurrency
  • IDOR testing across authenticated identities
  • +1 more
Read the update

v5.2

February 12, 2026

Detection

90+ SAST rules across Python, JavaScript, Java and Go

Static analysis with rules written against real exploit conditions rather than pattern matches, wired to the same validation and ranking as everything else.

  • 90+ security rules, four languages
  • Taint tracking from source to sink
  • Secret detection with entropy and format checks
Read the update

v5.0

February 3, 2026

Detection

DAST for applications that stopped being pages

GraphQL, WebSocket and single-page application scanners ship together, so the parts of a modern application a crawler never reached are now tested like the rest of it.

  • GraphQL scanner
  • WebSocket scanner
  • SPA-aware crawling
Read the update

v4.0

January 31, 2026

Accuracy

Nothing gets reported until it has been exploited

Every candidate finding is now validated by replay before it reaches your queue. Unreproducible candidates are dropped rather than downgraded, which is what takes a scanner queue from thousands to dozens.

  • Validation replay before reporting
  • LLM-assisted triage with evidence grounding
  • Suppression with recorded reasoning
Read the update

v3.0

January 21, 2026

Workflow

Security testing that runs in the pull request

SARIF output, inline PR annotations and configurable merge blocking bring findings to the engineer who wrote the code, at the moment they can still change it cheaply.

  • SARIF output
  • Pull request annotations
  • Configurable merge blocking
  • +1 more
Read the update

v2.0

December 14, 2025

Coverage

Active Directory and OSINT, in the same assessment

Internal path enumeration and external footprint discovery join the same engine, so the route from a leaked credential to a domain controller is one graph rather than two reports.

  • Active Directory attack path enumeration
  • Kerberos and certificate abuse checks
  • Lockout-aware credential testing
  • +1 more
Read the update

Staying current

How to keep up with releases

Upgrade the package

Updates ship to PyPI. Everything on this page is available to anyone on the current version.

pip install --upgrade aiptx

Read the release notes

Every version with its features, improvements, fixes and anything that needs action before upgrading.

Open the changelog

Sessions worth an hour

Practical sessions on penetration testing, API security and running an assessment programme. Live with real Q&A, and available on demand afterwards.

See the session slate

See Your Attack Surface in Real-Time

Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.