Ross ROSS = Recommend OSS · open-source software intelligence for agents

OWASP/Nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management observed · 2026-08-28

github.com/OWASP/Nettacker · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 99
  • Release rhythm 67
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 696
  • age_days: 3421
  • days_rel: 9
  • days_push: 8
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

5535 stars · 1156 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scanning, and network security audits. It offers modular scans (port scanning, service detection, subdomain enumeration, brute-forcing) via CLI, REST API, and Web UI, with reports in HTML, JSON, CSV, and text.

Use cases

  • scan a network for open ports and running services
  • enumerate subdomains of a target domain
  • brute-force credentials on SSH, FTP, or SMTP services
  • run automated vulnerability assessments against web applications and APIs
  • audit IoT devices for known CVEs
  • detect new hosts or open ports by comparing scans over time
  • generate pentest reports in HTML or JSON

When to choose

  • you need an all-in-one automated recon and vulnerability scanning framework
  • you want CLI, REST API, and Web UI access to scanning capabilities
  • you need multi-protocol scanning (HTTP, SSH, SMB, FTP, SMTP, ICMP) with parallel execution
  • you want scan history stored in a database for drift detection in CI/CD

When to avoid

  • you need a deep manual exploitation framework like Metasploit
  • you only need a single-purpose fast port scanner like nmap
  • you lack authorization to test the target systems
  • you need a GUI-only vulnerability management platform

Facets

cli-tool · maturity active

penetration-testing vulnerability-scanning security web-scraping cli api-framework http-client security penetration-testing networking iot python windows cli port-scanner recon bruteforce subdomain-enumeration vulnerability-management owasp cve information-gathering rest-api web-ui linux macos docker web-server

3 sources

Member repositories

RepositoryRoleHealth v2
OWASP/Nettackermain88

For agents

markdown · JSON · MCP: product_card(name="OWASP/Nettacker")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem