Web Application Security

Open-Source Web Scanners : A Detailed List Of Tools From GitHub And GitLab

A list of open source web security scanners on GitHub and GitLab, ordered by Stars. It does not provide in-depth analysis – for more analysis or a wider range of tools, see the links below.

Note that some large projects have multiple repos – in which case the second most relevant repo is included immediately after and is indented.

General Purpose Web Scanners

Tools which can find a range of ‘unknown’ vulnerabilities on any websites.

Main SiteLast CommitCommittersStars
ZAP
– ZAP Extensions
Hetty
W3af
Arachni
Astra
Wapiti
Skipfish
Sitadel
Taipan
Vega
Reaper
BrowserBruter
Tuplar
Ugly-duckling
Jawfish
Pākiki
Browserker

For more information click here.

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

git fetch vs git pull: How They Work and When to Use Each

Both git fetch and git pull talk to a remote repository, but they do very different things to your…

2 days ago

git cherry-pick Command: Apply Commits from Another Branch

Sometimes the change you need already exists, just on the wrong branch. A hotfix lands…

2 days ago

Best Email APIs for Secure Business Email: Why Developers Are Moving Beyond SMTP

Email is still one of the most important communication channels inside modern applications. Password resets,…

3 days ago

Nginx Commands in Linux: Start, Stop, Reload, Test, and Log

Nginx is a high-performance web server and reverse proxy trusted by some of the largest…

6 days ago

ufw Command in Linux: Manage Firewall Rules with Examples

ufw (Uncomplicated Firewall) sits on top of iptables (or nftables on newer systems) and replaces…

6 days ago

who Command in Linux: Show All Logged-In Users and Sessions

When you share a server with a team or investigate unexpected activity, the first question…

6 days ago