Home page logo


Wapiti allows you to audit the security of your web applications. It performs "black-box" scans; i.e., it does not study the source code of the application but will scans the webpages of the deployed webapp, looking for scripts and forms where it can inject data. Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable. For downloads and more information, visit the Wapiti homepage.

Popularity #121, new!
Rating ★★★½ (4)
Latest release 2.2.1
Dec. 29, 2009
(11 years, 3 months ago)


★★★★★ Clint

Has come a long way since the version 2 branch. Now at Version 3.03 it has become an excellent tool in the arsenal. The ability to easily setup and run against many targets and get the results in json have provided a way to automatically manage all of our apps.

★★★★★ sirius

Great Python tool, I love it ! I can't wait for the Python3 version.

By the way the last current stable version is 2.3.0.

★★ vidhi

Does Wapiti support mvc .net framework? Please help and provide assistance on same.

no rating saleem

@Rajsekhar -- here auth is for authorization of only sites that has basic and digest authorization

★★ Rajshekar

In the wapiti tool, when i provide the options for the authorization(--auth) the scan is not performed according to this. Can anybody help me out.

Your comment

Along with your rating, you can use the comment form to post a review, tutorial, tips and tricks, or anything else others will find useful. If you develop this software (or work for the company), please don't rate it. You may leave a clarifying comment as long as you state your affiliation and don't specify a star rating (just leave it as “No rating”).

  (will not be shown, will not be spammed)
(At least 50 characters. No markup is allowed. URLs will be made into links.)
 Which does not belong: buffer overflow, format string, sql injection, flux capacitor, cross-site scripting (antispam)

Feed for updates.


[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]