awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
w-digital-scanner avatar

w-digital-scanner/w13scan

0
View on GitHub↗
1,945 stars·366 forks·Smarty·GPL-2.0·14 views

W13scan

W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors.

The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect live HTTP and HTTPS traffic in real-time. Additionally, the tool performs web application fingerprinting by analyzing headers and page content to identify underlying frameworks and server technologies.

The system supports automated security assessments by integrating with external crawlers to discover endpoints and systematically map application surfaces. It provides deep visibility into web interactions by parsing request and response metadata, including headers, parameters, and cookies, to monitor for security weaknesses across various network environments.

Features

  • Web Application Scanning - Identifies vulnerabilities in web applications and CMS platforms through automated scanning.
  • Vulnerability Assessment Tools - Provides a modular scanning engine that executes security plugins against web endpoints to identify injection flaws and misconfigurations.
  • Vulnerability Scanning and Analysis - Identifies, scans, and manages security vulnerabilities across web endpoints.
  • Passive Scanners - Intercepts and inspects live HTTP and HTTPS traffic in real-time to automatically detect security flaws.
  • Intercepting Proxies - Intercepts and inspects HTTP traffic in real-time to identify security issues.
  • Traffic Proxying - Intercepts and inspects network traffic between systems for security analysis.
  • Automated Vulnerability Detection - Automatically identifies security weaknesses and misconfigurations in web services.
  • Web Vulnerability Scanners - Monitors web traffic through a proxy to detect vulnerabilities and identify application fingerprints automatically.
  • Out-of-Band Interaction Monitoring - Captures asynchronous network callbacks to identify blind vulnerabilities.
  • Blind Injection Scanners - Detects vulnerabilities by monitoring external callbacks for non-visible injection execution.
  • Web Application Security Assessments - Performs automated analysis of web application structures, headers, and content to identify security vulnerabilities.
  • Blind Injection Callbacks - Detects successful blind injection vulnerabilities by monitoring external network callbacks.
  • Passive Scanning Tools - Enhances automated scanning capabilities through passive traffic analysis.
  • Security Analysis Proxies - Intercepts request and response metadata to perform real-time security monitoring of web application interactions.
  • Vulnerability Probing Modules - Executes specialized security modules designed to probe for specific vulnerabilities and systemic weaknesses.
  • Active Scanning Engines - Actively sends payloads to endpoints to identify vulnerabilities through server behavior.
  • Application Fingerprinters - Identifies the software stack powering a website by matching HTTP responses against a library of known signatures.
  • Modular Plugin Architectures - Provides an architectural framework designed for extensibility via security plugins.
  • Callback Platforms - Utilizes a dedicated callback service to track and verify vulnerabilities that do not provide immediate feedback.
  • Security Crawlers - Maps web application attack surfaces and identifies injection points through automated discovery engines.

Star history

Star history chart for w-digital-scanner/w13scanStar history chart for w-digital-scanner/w13scan

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with W13scan

These projects share indexed features with W13scan. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • s0md3v/xsstrikes0md3v avatar

    s0md3v/XSStrike

    14,752View on GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Pythonwaf-detectionxssxss-bruteforce
    View on GitHub↗14,752
  • sofianehamlaoui/lockdoor-frameworkSofianeHamlaoui avatar

    SofianeHamlaoui/Lockdoor-Framework

    1,540View on GitHub↗

    Lockdoor-Framework is a modular penetration testing suite designed to facilitate comprehensive security assessments through a centralized command-line interface. It functions as an integrated platform for reconnaissance, vulnerability scanning, and the exploitation of target systems, providing a unified environment for managing complex security workflows. The framework distinguishes itself through a modular plugin architecture that allows for the extension of core capabilities without modifying the underlying codebase. It incorporates an automated reconnaissance pipeline to map attack surface

    Pythonblackarch-packagesblueteamingcyber-security
    View on GitHub↗1,540
  • dstotijn/hettydstotijn avatar

    dstotijn/hetty

    11,485View on GitHub↗

    Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit

    Go
    View on GitHub↗11,485
  • yaklang/yakityaklang avatar

    yaklang/yakit

    7,386View on GitHub↗

    Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun

    TypeScriptblueteamburpsuiteexploit
    View on GitHub↗7,386
Compare all 30 related projects→

Frequently asked questions

What does w-digital-scanner/w13scan do?

W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors.

What are the main features of w-digital-scanner/w13scan?

The main features of w-digital-scanner/w13scan are: Web Application Scanning, Vulnerability Assessment Tools, Vulnerability Scanning and Analysis, Passive Scanners, Intercepting Proxies, Traffic Proxying, Automated Vulnerability Detection, Web Vulnerability Scanners.

Which projects share features with w-digital-scanner/w13scan?

Projects with overlapping indexed features include: s0md3v/xsstrike — XSStrike is an automated security scanning engine designed for web application discovery, input. sofianehamlaoui/lockdoor-framework — Lockdoor-Framework is a modular penetration testing suite designed to facilitate comprehensive security assessments… dstotijn/hetty — Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic… yaklang/yakit — Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… jasonxtn/argus — Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping…

Curated searches featuring W13scan

Hand-picked collections where W13scan appears.
  • SQL injection scanners
  • Automated Web Application Vulnerability Scanners
  • Template-Based CVE Vulnerability Scanners