awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
urbanadventurer avatar

urbanadventurer/WhatWeb

0
View on GitHub↗
6,424 stars·979 forks·Ruby·gpl-2.0·15 viewswww.morningstarsecurity.com/research/whatweb↗

WhatWeb

WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names.

The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content without sending additional requests, while aggressive plugins probe extra URLs and check file hashes for deeper verification. WhatWeb also supports adjustable scan aggression levels to balance speed and thoroughness, concurrent scanning of multiple targets, and the ability to route traffic through a proxy or TOR for anonymity.

For extensibility, WhatWeb allows creation of custom detection plugins using text patterns, regular expressions, MD5 hashes, or Google dork queries directly on the command line. Scan results can be filtered by custom criteria, and output is logged to multiple formats including JSON, XML, SQL, MongoDB, and Elasticsearch for integration with external analysis pipelines.

Features

  • Application Fingerprinters - Identifies the software stack powering a website by matching HTTP responses against a library of over 1800 signatures.
  • Web Technology Signature Matchers - Matches HTTP responses against over 1800 signatures to identify CMS platforms, libraries, and servers.
  • Scan Aggression Levels - Controls the trade-off between scan speed and thoroughness by adjusting request depth per target.
  • HTTP Response Fingerprint Extractors - Extracts software versions, user accounts, and hardware metadata from HTTP headers and page content.
  • Text Pattern Matching - Searches for literal strings or regular expressions in HTML and HTTP headers to identify technologies.
  • Passive and Aggressive Modes - Provides both passive analysis of existing responses and aggressive probing of additional URLs for verification.
  • Hybrid Analysis Scanners - Identifies technologies through HTTP header analysis alone or by probing additional URLs for deeper verification.
  • Security Reconnaissance Tools - Probes websites to enumerate software versions, user accounts, and misconfigurations for vulnerability assessment.
  • Detection Plugin Interfaces - Supports custom detection rules using text patterns, regular expressions, MD5 hashes, and Google dork queries for extensible scanning.
  • Metadata Scanners - Probes websites to detect software versions, user accounts, and technical metadata from HTTP headers and page markup.
  • Web Server Fingerprinting - Recognizes web server software by analyzing HTTP response headers and known server fingerprints.
  • Web Application Fingerprinters - Scans HTTP responses to detect known CMS platforms, forums, and other web applications by matching fingerprints.
  • Web Technology Detection - Identifies web technologies by analyzing HTTP headers and page content without sending additional requests.
  • Version Number Extractors - Extracts version numbers from matched patterns and returns them as part of plugin output.
  • Concurrent Target Managers - Enables parallel scanning of many websites simultaneously with adjustable concurrency and timeouts.
  • Device and Hardware Identification - Matches HTTP headers and server banners against known signatures to recognize routers, webcams, and embedded devices.
  • Obscured Platform Detectors - Uses multiple tests per technology, such as checking favicons and file paths, to identify hidden platforms.
  • Scan Result Exporters - Outputs scan findings to JSON, XML, SQL, MongoDB, and Elasticsearch for integration with analysis pipelines.
  • Scan Log Exporters - Outputs scan results to JSON, XML, SQL, MongoDB, and Elasticsearch for integration with analysis pipelines.
  • Scan Configurations - Adjusts the number of HTTP requests per target to balance speed and thoroughness during scans.
  • Aggression Level Selectors - Adjusts scan aggression levels to balance speed and thoroughness from a single request to deep probing.
  • Web Version Extractors - Reads version information from headers, meta tags, and file paths to report exact software versions.
  • Probing Plugins - Ships aggressive plugins that fetch extra URLs and check file hashes to confirm software identity.
  • Scan Result Exporters - Exports scan results to JSON, XML, SQL, or Elasticsearch for integration with analysis pipelines.
  • Scanning Performance Tuning - Tunes concurrency, timeouts, and output buffering to optimize scan speed and stability.
  • Concurrent Target Scanners - Scans many websites concurrently with adjustable thread counts and timeouts for large-scale reconnaissance.
  • Embedded Web Interface Fingerprinters - Recognizes the web interfaces of routers, cameras, and other embedded devices by matching unique fingerprints.
  • Google Dorking Techniques - Uses Google Hacking Database query strings as signatures to identify web applications during scans.
  • Tor Routing - Channels all HTTP traffic through a proxy server, including TOR, for anonymity during scans.
  • Scan Filtering Tools - Limits scan results to targets matching custom text strings, regular expressions, or specific plugins.
  • Embedded Third-Party Service Detectors - Detects embedded third-party services such as analytics, JavaScript libraries, CAPTCHAs, video players, and widgets.
  • Ad-Hoc Detection Rules - Allows defining custom detection rules directly on the command line using text patterns or hashes.
  • Username Extractors - Returns detected usernames from matched patterns as part of plugin output.
  • Module Name Extractors - Returns detected module or component names alongside the main system identification.
  • Web Metadata Extractors - Retrieves version numbers, email addresses, account IDs, and SQL errors from website responses and markup.
  • Module Name Capturers - Captures module names from matched patterns and returns them as the plugin's module field.
  • Content Hash Matchers - Identifies systems by computing MD5 hashes of URL content and comparing to known values.
  • Multi-Format Exporters - Exports scan findings to JSON, XML, SQL, MongoDB, and Elasticsearch for external tool integration.
  • Open Source Intelligence - Fingerprinting tool for identifying website technologies.
  • Fingerprinting Tools - Tool for identifying web application frameworks and versions.
  • Technology Fingerprinting - Next-generation web technology scanner.
  • Network and Web Reconnaissance - Fingerprints web applications and servers.
  • Security And Privacy - Website fingerprinter.
  • Security Tools - Next-generation web scanner for fingerprinting
  • Technology Fingerprinting - Identifies web technologies and CMS platforms on target websites.
  • Web Application Analysis - Scanner for identifying web technologies and CMS versions.

Star history

Star history chart for urbanadventurer/whatwebStar history chart for urbanadventurer/whatweb

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does urbanadventurer/whatweb do?

WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names.

What are the main features of urbanadventurer/whatweb?

The main features of urbanadventurer/whatweb are: Application Fingerprinters, Web Technology Signature Matchers, Scan Aggression Levels, HTTP Response Fingerprint Extractors, Text Pattern Matching, Passive and Aggressive Modes, Hybrid Analysis Scanners, Security Reconnaissance Tools.

What are some open-source alternatives to urbanadventurer/whatweb?

Open-source alternatives to urbanadventurer/whatweb include: projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… s0md3v/arjun — Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… aboutcode-org/scancode-toolkit — ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source… google/tsunami-security-scanner — Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity…

Open-source alternatives to WhatWeb

Similar open-source projects, ranked by how many features they share with WhatWeb.
  • projectdiscovery/naabuprojectdiscovery avatar

    projectdiscovery/naabu

    5,766View on GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    View on GitHub↗5,766
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    View on GitHub↗13,105
  • s0md3v/arjuns0md3v avatar

    s0md3v/Arjun

    6,086View on GitHub↗

    Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large dictionaries of parameter names against target URLs. It systematically probes endpoints using GET, POST, JSON, and XML request formats to find which parameters the server accepts, and can detect parameters whose values appear reflected in the response body. The tool distinguishes itself through its multi-method scanning approach, passive parameter collection from public archives like OTX and CommonCrawl, and its ability to detect value-sensitive parameters that only trigger a response

    Pythonapi-fuzzerapi-fuzzingapi-testing
    View on GitHub↗6,086
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • See all 30 alternatives to WhatWeb→