
OpenDoor v5.18.0
OWASP Web Recon & Directory Discovery Platform
OpenDoor — OWASP Web Recon & Directory Discovery Platform

OpenDoor is an open-source CLI Recon Platform for authorized web reconnaissance, directory discovery, subdomain enumeration, fingerprints, WAF detection, bypass probing, response filtering, reporting, open-redirect checks, bounded crawl and transport-based scanning workflows.
It helps security researchers, penetration testers, bug bounty hunters, DevSecOps engineers, and developers identify exposed paths, login panels, directory listings, restricted resources, backup files, web shells, subdomains, and other potentially sensitive web assets.
Use OpenDoor only on systems you own or have explicit permission to test.
✅ Project status
🧪 CI matrix
| Platform | Python 3.12 | Python 3.13 | Python 3.14 |
|---|---|---|---|
| Linux | |||
| macOS | |||
| Windows |
🚀 Quick links
- Documentation
- Quickstart
- Installation and update
- Usage guide
- Practical examples
- Changelog
- PyPI package
- Homebrew formulae
- Docker image
- AUR package
- BlackArch package
- Issues
- Contributors
✨ Features
- directory discovery;
- recursive directory discovery;
- bounded same-origin crawl;
- redirects following;
- subdomain enumeration;
- multi-threading scans for faster lookups;
- single target, target file, stdin, IPv4 CIDR, and IPv4 range input modes;
- custom wordlists, prefixes, shuffling to break scan patterns and extension filters, remote wordlists supports;
- custom request headers, cookies forwarding, and raw HTTP request templates;
- response filters by status, size, text, regex, and body length;
- response sniffers for detecting directory listings, empty responses, known file exposures, active shadow-copy probes, collation, possible exposed secrets, client-exposed endpoints, errors, exposed debug stack traces, and verified open redirect vulnerabilities;
- smart auto-calibration for soft-404, wildcard, catch-all, semantic response-diff, and DNS wildcard cases;
- technology fingerprint detection for CMS, ecommerce platforms, frameworks, runtime stacks, infrastructure, and HSTS posture;
- passive privacy-risk checks in
--fingerprint, including possible HSTS, ETag/cache, and supercookie surfaces. - passive WAF detection and bypass in secure scanning mode;
- WAF guard stop condition for ending low-value scans when initial classified responses are overwhelmingly WAF-blocked;
- controlled header and path bypass probes for blocked
401and403resources; - fault-tolerant scan runtime with retries, fail-streak protection, transport failure handling, resumable sessions, and runtime pause/resume controls;
- CI/CD fail-on result bucket rules;
- differential report comparison for previous/current JSON or SQLite reports;
- reports in terminal, text, JSON, CSV, HTML, SARIF and SQLite formats;
- proxy, OpenVPN, WireGuard, legacy TLS, and mTLS client-certificate transport support;
- sequential per-target transport rotation for batch workflows;
- configuration wizard for repeatable scan profiles;
- built-in wordlists (upd. 2026-08)
🧭 Where does OpenDoor make sense?
It is designed for real targets where speed alone is not enough: WAFs, CDNs, soft-404 pages, wildcard routes, restricted resources, authenticated areas, unstable networks, multi-target batches, and transport-controlled scans. Since it first launch in 2016 to the present day, the OpenDoor has changed dramatically, growing from a primitive brute forcer into a new adaptive discovery framework. Became DevOps and QA friendly. OpenDoor focuses on context-aware discovery instead of blind enumeration.