
Wapiti
Wapiti is the better choice when you want a broad black-box web application audit, rather than a scanner focused on one vulnerability class. It crawls applications and fuzzes discovered inputs for XSS, SQLi, file disclosure, command injection, SSRF, and several other issues, making it useful early in an assessment. The trade-off is that its breadth can mean more noise than specialized scanners, so we'd use it for initial coverage and attack-surface mapping, then validate interesting findings with more focused tools.
Read the rest for free
Leave your email to see the full write-up for Wapiti, the download details and every other tool on the site. You will also get the weekly brief. One email a week, unsubscribe from any of them.
We use your address for the brief and nothing else, and never pass it on. See the privacy policy.