I don't do web apps. So, all I could do is DuckDuckGo for some terms that might get results. Found claim about using automated, open-source scanners to find IDOR and a lot of other stuff here:
They do note that IDOR poses some difficulties with it needing heuristics that might have high, false positives. The tools are in the references section toward the bottom. Try them out.
http://www.zemris.fer.hr/~sgros/publications/diploma_thesis/...
They do note that IDOR poses some difficulties with it needing heuristics that might have high, false positives. The tools are in the references section toward the bottom. Try them out.