# urbanadventurer/WhatWeb

Next generation web scanner

Repository: https://github.com/urbanadventurer/WhatWeb
Canonical: https://ross.abutalabs.com/products/whatweb
Homepage: https://www.morningstarsecurity.com/research/whatweb
Language: Ruby
License: GPL-2.0
License Family: copyleft
Topics: security, web, scanner, ruby, penetration-testing, kali-linux, owasp, penetration-testing-tools, penetration-test, hacking, hacking-tools, network-security, recon, appsec, application-security, pentesting, pentesting-tools, pentest, web-hacking, security-tools
Last push: 2026-04-02T15:43:24+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 75, release rhythm 65, longevity 100
- inputs: {"age_days": 5816, "days_push": 153, "days_rel": 153, "gap_med": 53, "n_releases_24m": 4}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6800, forks 1007 (observed 2026-08-28T04:09:48.693652+00:00)

## What it is
WhatWeb is a command-line web scanner that identifies the technologies powering websites, including CMSs, web servers, JavaScript libraries, and analytics packages, using over 1800 plugins. It supports adjustable aggression levels, from fast stealthy single-request scans to thorough penetration-test modes, and detects version numbers, email addresses, and SQL errors.

## Use cases
- identify what technologies a website is built with
- fingerprint CMS and web server versions during recon
- detect WordPress sites even with generator tags removed
- enumerate web technologies across many target URLs
- gather reconnaissance before a penetration test
- find exposed email addresses and SQL errors on a site

## When to choose
- you need fast, scriptable web technology fingerprinting from the CLI
- you want a large plugin ecosystem covering CMSs, servers, and frameworks
- you are doing recon or appsec assessment on public websites
- you need a tool available in Kali Linux and other pentest toolkits

## When to avoid
- you need a full vulnerability scanner rather than technology identification
- you want a GUI-driven scanning experience
- you need authenticated or deep crawling of web applications
- you require active exploitation capabilities

## Facets
- artifact type: cli-tool
- maturity: stable
- function: security, penetration-testing, http-client, web-scraping
- domain: security, penetration-testing, web-development, developer-tools
- platform: windows, cli, ruby
- tags: web-fingerprinting, recon, technology-detection, owasp, kali-linux, appsec, linux, macos

## Member repositories
- urbanadventurer/WhatWeb (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:48.693652+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:42:05.615364+00:00, confidence not recorded.
  - readme: https://github.com/urbanadventurer/WhatWeb (fetched 2026-08-28T04:09:48.693652+00:00, sha 17ba2522ace6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
