OWASP ZAP
A free open web-application security scanner with a proxy, spiders, active and passive rules, API scanning, an automation framework, add-ons, and CI-friendly Docker images.
Why use it
Indie games with accounts, leaderboards, payments, or content administration can repeat DAST against HTTP surfaces and catch configuration, header, and input problems missed by unit tests.
Where it fits
Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.
What to check
Active scans send hostile requests and must run only against authorized, recoverable test systems; authentication, business logic, and false positives need human analysis, and rules require updates.