A list of open source web security scanners on GitHub.
Tools which can find a range of 'unknown' vulnerabilities on any websites.
| Main Site | Last Commit | Committers | Stars |
|---|---|---|---|
| Arachni | |||
| Astra | |||
| Ffuf | |||
| Hetty | |||
| Jawfish | |||
| Sitadel | |||
| Skipfish | |||
| Taipan | |||
| Ugly-duckling | |||
| Vega | |||
| W3af | |||
| Wapiti | |||
| Wfuzz | |||
| ZAP |
Tools which can find a range of 'known' vulnerabilities on any websites.
| Main Site | Last Commit | Committers | Stars |
|---|---|---|---|
| Nikto | |||
| Nuclei | |||
| Spaghetti | |||
| Striker | |||
| Yasuo |
Tools which can find a range of 'known' vulnerabilities on one or more CMS websites.
| Main Site | Last Commit | Committers | Stars |
|---|---|---|---|
| Clusterd | |||
| CMSScan | |||
| Droopescan | |||
| JoomScan | |||
| Volnx | |||
| WPscan |
PR's welcomed - template line (replace USER/REPO):
| []() | [](https://github.com/USER/REPO/commits) | [](https://github.com/USER/REPO/graphs/contributors) | [](https://github.com/USER/REPO/stargazers) |