# w-digital-scanner/w13scan

Passive Security Scanner (被动式安全扫描器)

Repository: https://github.com/w-digital-scanner/w13scan
Canonical: https://ross.abutalabs.com/products/w13scan
Language: Smarty
License: GPL-2.0
License Family: copyleft
Topics: security-tools, passive-vulnerability-scanner
Last push: 2023-02-08T03:30:28+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2624, "days_push": 1302, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1946, forks 364 (observed 2026-08-28T04:05:57.767353+00:00)

## What it is
W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with a rich set of detection plugins covering XSS, SQL injection, command injection, sensitive file leaks, and more.

## Use cases
- scan websites for xss vulnerabilities
- detect sql injection in web apps
- passively scan traffic through a proxy for vulnerabilities
- find sensitive file leaks and backup files on a site
- detect struts2 and fast vulnerabilities
- find command injection flaws in web parameters

## When to avoid
- you need a commercial-grade scanner with support and compliance reporting
- you need active crawling with heavy JavaScript rendering built in
- you cannot legally or ethically scan the target

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, penetration-testing, vulnerability-scanning, http-client, web-scraping
- domain: security, penetration-testing, web-development, developer-tools
- platform: python, windows, cli
- tags: passive-scanner, web-vulnerability-scanner, xss, sql-injection, proxy-based-scanning, security-audit, linux, macos

## Member repositories
- w-digital-scanner/w13scan (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:57.767353+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:07:21.392619+00:00, confidence not recorded.
  - readme: https://github.com/w-digital-scanner/w13scan (fetched 2026-08-28T04:05:57.767353+00:00, sha a85ff86324f4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
