30 open-source projects similar to m4ll0k/wascan, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.
WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the
CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.
W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors. The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect l
This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin
A free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan.
A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.
Detect and bypass web application firewalls and protection systems
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
GyoiThon is a growing penetration test tool using Machine Learning.
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
safely install npm packages by auditing them pre-install stage
Guarantee Node.js disclosed the CVEs after a Security Release
Audits an NPM package.json file to identify known vulnerabilities.
Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ
A Ruby framework designed to aid in the penetration testing of WordPress systems.
CLI tool that scans dependency files for EOL status, CVE risk, and health grade
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/
Striker is an offensive information and vulnerability scanner.
XSStrike is an automated security scanning engine designed for web application discovery, input
Detect security flaws in Joi validation schemas (XSS, SQL injection, ...) 🔥