Wapiti
Free and open-source web-application vulnerability scanner in Python
Wapiti is a free and open-source command-line tool for auditing the security of websites and web applications through black-box scans. It crawls a deployed web application to collect URLs, forms, and scripts, then injects payloads to detect vulnerabilities such as SQL and XPath injection, XSS, file disclosure, command execution, XXE, CRLF injection, CSRF, open redirects, and Log4Shell. It supports GET and POST methods, multipart forms, and payload injection in uploaded filenames.
The tool includes modules for security header and cookie flag checks, web application fingerprinting via the Wappalyzer database, WordPress and Drupal module enumeration, brute-force login testing with a dictionary, and detection of uncommon HTTP methods. Scans can be suspended and resumed using SQLite sessions, and reports are generated in HTML, XML, JSON, TXT, and CSV formats. It supports HTTP, HTTPS, and SOCKS5 proxies, several authentication methods, and configurable crawler limits.
Wapiti is a command-line application released under the GNU General Public License version 2. It can be installed via PIP, and a cookie-fetching utility called wapiti-getcookie is included.
12 alternatives to Wapiti
Ranked by how well each tool replaces Wapiti: shared features, audience, price and popularity.
- 60 out of 100 matchContact sales
Free and open source utility for network discovery and security auditing.
Covers 0 of 15 key features.
Free planOpen source60 out of 100 matchContact salesWordPress security plugin with firewall, malware scanning, and threat intelligence.
Covers 2 of 15 key features.
Free plan56 out of 100 matchContact salesFree browser and plugin vulnerability scanning tool
Covers 2 of 15 key features.
Free plan55 out of 100 matchContact salesThe fastest and smartest vulnerability mitigation for websites
Covers 3 of 15 key features.
55 out of 100 match$69/moA complete suite of tools for assessing WiFi network security
Covers 1 of 15 key features.
Open source55 out of 100 match—A SUID program that restricts the running environment of untrusted applications using the
Covers 2 of 15 key features.
Free planOpen source55 out of 100 matchContact salesWeb application and API security scanner using dynamic testing (DAST) with proof-based, AI
Covers 0 of 15 key features.
54 out of 100 matchContact sales- 54 out of 100 matchContact sales
WordPress security plugin that blocks bots, protects customers, and secures sites
Covers 1 of 15 key features.
Free plan53 out of 100 matchFreeHosted vulnerability scanners and network tools for attack surface discovery and security.
Covers 1 of 15 key features.
Free plan53 out of 100 match$10/mo