#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

The Swiss Army knife for automated Web Application Testing

Hack the World using Termux

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast web fuzzer written in Go

Go-based CLI scanner for web cache poisoning and deception. Supports 10 poisoning techniques, multiple deception methods, built-in crawler, JSON…

Most advanced XSS scanner.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Web vulnerability scanner written in Python3

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

Automatic SQL injection and database takeover tool

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Nikto web server scanner

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Next generation web scanner

Fast and easy-to-use directory brute-forcer written in Go.