wapiti-scanner/wapiti
Web vulnerability scanner written in Python3 observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 98
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 20.0
- age_days: 2279
- days_rel: 14
- days_push: 14
- n_releases_24m: 13
Adoption not part of the score
1846 stars · 268 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and forms with payloads to detect vulnerabilities. It covers a wide range of attacks (SQLi, XSS, command injection, SSRF, XXE, CSRF, etc.) and generates reports in multiple formats.
Use cases
- scan my website for vulnerabilities
- find SQL injection and XSS in a web app
- audit security of a deployed web application
- detect Log4Shell and Spring4Shell on my servers
- fuzz web forms for injection flaws
- generate a security report for a web app
- enumerate CMS versions and related CVEs
When to choose
- you need a free, scriptable black-box scanner for web apps
- you want CLI-based scanning with resumable sessions and multiple report formats
- you need broad payload coverage (SQLi, XSS, SSRF, XXE, CRLF, etc.) without source code access
When to avoid
- you need static/source-code security analysis (SAST)
- you require an authenticated enterprise DAST with GUI dashboards and compliance reporting
- you want continuous runtime protection rather than periodic scanning
Facets
cli-tool · maturity active
penetration-testing vulnerability-scanning web-scraping security security penetration-testing web-development python cli cross-platform black-box-scanner fuzzer web-security-audit xss sql-injection owasp linux macos
2 sources
- readme: https://github.com/wapiti-scanner/wapiti · fetched 2026-08-28 · ef6ae200c7a5
- homepage: https://wapiti-scanner.github.io/ · fetched 2026-08-29 · b1d34ccf53f5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| wapiti-scanner/wapiti | main | 98 |
For agents
markdown · JSON · MCP: product_card(name="wapiti-scanner/wapiti")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem