Tech riderRev. 3 Oct 2026
- 1Runs onAPI, Linux, Mac, self-hosted, Windows
- 2CostsFree plan
- 3Deploymenton-premise
- 4Authenticated scansYes
- 5JavaScript crawlingYes
- 6API scanningYes
6 lines stated Written from the maker's own pages: wapiti.sourceforge.io, github.com

Overview
Wapiti is ranked #9 of 31 in web application security scanners on Specifiction. It runs on API, Linux, macOS, Self-hosted, Windows. There is a free plan.
Wapiti plans and pricing
All plansCompared on web application security scanners
- Free plan
- Yeswapiti.sourceforge.io
- Deployment
- on-premisewapiti.sourceforge.io
- Authenticated scans
- Yeswapiti.sourceforge.io
- JavaScript crawling
- Yeswapiti.sourceforge.io
- API scanning
- Yeswapiti.sourceforge.io
Facts
- Purpose
- Wapiti is a Python web vulnerability scanner that audits websites and web applications.github.com · 3 Oct 2026
- Scan method
- It crawls deployed web applications and tests links, forms, and scripts with payloads without examining source code.github.com · 3 Oct 2026
- Vulnerability coverage
- Its listed checks include SQL and XPath injection, XSS, file disclosure, command execution, XXE, SSRF, and open redirects.github.com · 3 Oct 2026
- Reports
- It generates reports in HTML, XML, JSON, TXT, CSV, and Markdown formats.github.com · 3 Oct 2026
- Authentication
- It supports Basic, Digest, and NTLM authentication, login forms, browser cookie imports, and custom Python code for complicated authentication cases.github.com · 3 Oct 2026
- Traffic and scan controls
- It supports HTTP, HTTPS, and SOCKS5 proxies, configurable scan scope, crawler limits, and custom HTTP headers.github.com · 3 Oct 2026
- Scan sessions
- It can suspend and resume scans using sessions stored in SQLite databases.github.com · 3 Oct 2026
- Requirements
- The README lists Python 3.12, 3.13, or 3.14 as requirements and says Windows use can be done through WSL.github.com · 3 Oct 2026
- Installation
- The project homepage offers installation with pip install wapiti3.wapiti.sourceforge.io · 3 Oct 2026
- Support
- The project README directs users to its FAQ and invites bug reports through GitHub issues.github.com · 3 Oct 2026
- Safety and limits
- The README warns that assessments may cause target malfunctions, crashes, or data loss, and says users need the target owner's consent.github.com · 3 Oct 2026
- License
- The README states that Wapiti is released under the GNU General Public License version 2.github.com · 3 Oct 2026
- Latest listed release
- The project's SourceForge files page lists version 3.3.2 dated 2026-08-19.sourceforge.net · 3 Oct 2026
Best Wapiti alternatives
See all 20 All accessCh 01 Nuclei Free planLinuxMac Free to start7.4 All accessCh 02 Qualys External Attack Surface Management Free trialAPILinux 7.4 All accessCh 03 Beagle Security Free planFree trialAPI from $99/mo7.2 All accessCh 04 Detectify Surface Monitoring Free planFree trialAPI from €208.33/mo7.2 All accessCh 05 Pentest-Tools.com API Scanner Free trialAPILinux from $95/mo7.2 All accessCh 06 ZeroThreat Free planFree trialAPI from $100/mo7.2
Where it ranks on Specifiction
Is Wapiti yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/wapiti-scanner/wapiti/blob/master/READM· checked 3 Oct 2026
- wapiti.sourceforge.io· checked 3 Oct 2026
- sourceforge.net/projects/wapiti/files/· checked 3 Oct 2026


