Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Gixy-Next — Gixy-Next: NGINX Configuration Security Scanner & Performance Checker | Kitploit
Tools/GitHubGitHub/megamansec/gixy-next
Static AnalysisVulnerability ScannersConfiguration AuditingWeb SecurityCloud SecurityDevSecOpsHardware SecurityMisconfiguration
GitHubmegamansec/gixy-next

Gixy-Next

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

View Repository
18442817 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

Gixy-Next: NGINX Configuration Security Scanner for Security Audits

Overview

Gixy-Next Mascot Logo

Gixy-Next (Gixy) is an open-source NGINX configuration security scanner and hardening tool that statically analyzes your nginx.conf to detect security misconfigurations, hardening gaps, and common performance pitfalls before they reach production. It is an actively maintained fork of Yandex's Gixy. Gixy-Next's source code is available on GitHub.

Gixy-Next can also be run in the browser on this page. No download is needed; you can scan your configurations on the website (locally, using WebAssembly).

Quick start

Gixy-Next (the gixy or gixy-next CLI) is distributed on PyPI. You can install it with pip or uv:

# pip
pip3 install gixy-next
# uv
uv pip install gixy-next

You can then run it:

# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf

You can also export your NGINX configuration to a single dump file (see nginx -T Live Configuration Dump):

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -

Web-based scanner

Instead of downloading and running Gixy-Next locally, you can use this webpage and scan a configuration from your web browser (locally, using WebAssembly).

Scan with Docker

Gixy-Next is available as a Docker image from Docker Hub or GitHub Registry.

Scan a local config file by mounting it into the container:

# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf

Scan an NGINX live configuration dump:

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf

Scan from stdin:

# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -

What it can do

Gixy-Next can detect a wide range of NGINX security and performance misconfigurations across nginx.conf and included configuration files. The following plugins are supported:

  • [add_header_content_type] Setting Content-Type via add_header
  • [add_header_multiline] Multiline response headers
  • [add_header_redefinition] Redefining of response headers by "add_header" directive
  • [alias_traversal] Path traversal via misconfigured alias
  • [allow_without_deny] Allow specified without deny
  • [default_server_flag] Missing default_server flag
  • [error_log_off] error_log set to off
  • [hash_without_default] Missing default in hash blocks
  • [host_spoofing] Request's Host header forgery
  • [http2_misdirected_request] Missing HTTP/2 misdirected-request safeguard
  • [http_splitting] HTTP Response Splitting
  • [if_is_evil] If is evil when used in location context
  • [invalid_regex] Invalid regex capture groups
  • [low_keepalive_requests] Low keepalive_requests
  • [missing_worker_processes] Missing worker_processes
  • [mixed_case_variable] Mixed-case variable references
  • [origins] Problems with referer/origin header validation
  • [overlapping_captures] Overlapping captures in rewrite redirect/args context
  • [proxy_buffering_off] Disabling proxy_buffering
  • [proxy_pass_normalized] proxy_pass path normalization issues
  • [proxy_set_header_redefinition] Redefining of proxied request headers by "proxy_set_header" directive
  • [quic_bpf_reuseport] QUIC connections silently dropped after reload
  • [regex_redos] Regular expression denial of service (ReDoS)
  • [resolver_external] Using external DNS nameservers
  • [return_bypasses_allow_deny] Return directive bypasses allow/deny restrictions
  • [ssl_ecdh_curve] Post-quantum groups stop NGINX from starting on older OpenSSL
  • [ssl_stapling_letsencrypt] OCSP stapling does nothing for a Let's Encrypt certificate
  • [ssl_stapling_without_resolver] OCSP stapling silently fails without a resolver
  • [ssrf] Server Side Request Forgery
  • [stale_dns_cache] Outdated/stale cached DNS records used in proxy_pass
  • [status_page_exposed] Ensures that status_page is not exposed to the world
  • [try_files_is_evil_too] try_files directive is evil without open_file_cache
  • [unanchored_regex] Unanchored regular expressions
  • [unnamed_groups] Unnamed capture groups in rewrite query string
  • [valid_referers] none/blocked in valid_referers
  • [version_disclosure] Using insecure values for server_tokens
  • [worker_rlimit_nofile_vs_connections] worker_rlimit_nofile must be at least twice worker_connections

Something not detected? Please open an issue on GitHub with what's missing!

Usage (flags)

gixy defaults to reading a system's NGINX configuration from /etc/nginx/nginx.conf. You can also specify the location by passing it to gixy:

# Analyze the configuration in /opt/nginx.conf
gixy /opt/nginx.conf

You can run a focused subset of checks with --tests:

Download Tool