Comparer
Diff two responses by line, word, or character (or by structure), mask the tokens that cause false positives, and confirm blind injection from a baseline/true/false triple.
Comparer diffs two HTTP responses so you can see exactly what changed between two requests. Pick two flows (filter them with a query) or paste content directly.

Diff modes and views
Diff at line, word, or character granularity. View the result three ways:
- Diff — a git-style view with added / removed / changed lines and counts.
- Parsed — header summary plus syntax-highlighted body panels.
- Hex — a byte-level diff that highlights the differing ranges ("N bytes differ").
Hugin also scores how similar the two responses are, with a match count and a structured list of differences.
Compare structure, not bytes
A line or character diff reads the body as plain text. When the body has
structure, tell Comparer to compare the structure instead — reordered fields,
reindented markup, and a token that changes in an attribute stop counting as
changes. Set the body type to json, html, xml, or binary and the
similarity score follows whichever comparison you pick.
Parses both bodies and compares the set of field values. Two responses with the same fields in a different key order score as identical, so only a real value or field change registers. Falls back to a text diff if a body isn't valid JSON.
Compares the tag skeleton — the sequence of tag names — and ignores attribute values and text. A rotating CSRF token in a hidden field, a changing nonce, or edited copy won't read as a difference; an added or removed element will. Use it when structure is the signal and the text is noise.
The same tag-skeleton comparison as HTML — structure only, attribute values and text ignored.
For non-text bodies like images or octet-streams: compares the two for exact equality and by size. No structure is read — you get same-or-different plus the length gap.
Mask out the noise that fakes a difference
The single biggest source of false positives is content that changes on every response: CSRF tokens, timestamps, nonces, request ids, view-state. Left in, they dominate both the diff and the similarity score, and the change you came for hides in the churn.
Hand Comparer a list of regex patterns (ignore_patterns) and it replaces every
match in both responses with a placeholder before it diffs or scores them.
Mask the token, the timestamp, the nonce, and what's left is the change you're
hunting. Patterns that don't compile are skipped, so one bad regex never aborts
the comparison.
This pays off most in blind detection: a value that differs on every response can swallow the true/false similarity gap and flip the verdict. Mask it, and the gap reflects only the injection.
More comparison options
Comparer already ignores the volatile headers that always differ — Date,
Set-Cookie, ETag, Last-Modified, Age, Expires, and the X-Request-Id /
X-Correlation-Id / X-Trace-Id family — so they never show as differences. Add your
own with excluded_headers.
ignore_case compares the two bodies case-insensitively.
normalize_whitespace collapses runs of spaces, tabs, and newlines to a single
space, so a reindented or reflowed body isn't flagged as changed.
Comparer flags a response-time gap over one second as one of the differences — a cheap signal when you're watching for time-based blind injection.
The structure modes and the masking patterns travel in the request you send to Comparer's API, not in the GUI toolbar. In the window you get the visual diff, the Parsed and Hex views, the similarity score, and blind detection. Comparer is also an MCP tool, so an AI agent can run a compare, a blind-detect, or a similarity check for you.
Blind injection detection
Give Comparer a baseline, a true response, and a false response and it tells you whether the endpoint is vulnerable, with a confidence and the true/false similarity gap — the fast way to confirm a blind SQLi or boolean-based bug without eyeballing diffs.
If the responses carry per-request tokens, mask them first so the gap reflects the injection, not the noise.
Swap sides, sync-scroll, and keep multiple comparisons in tabs. "Explain differences" hands the diff to the Copilot (Pro).