#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

Automatic SQL injection and database takeover tool
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Fast web fuzzer written in Go

Web path scanner

A next-generation crawling and spidering framework.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Nikto web server scanner

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Most advanced XSS scanner.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, simple, recursive content discovery tool written in Rust.

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…