description Wapiti Overview
Wapiti is an open-source, automated website performance testing tool that simulates real browser usage to measure page load times and identify bottlenecks across various network conditions and devices.
help Wapiti FAQ
Is Wapiti a website performance or page-speed testing tool?
Wapiti is a black-box web application vulnerability scanner written in Python, not a page-speed measurement framework. It crawls deployed pages and forms, injects test payloads, and looks for errors or abnormal behavior.
Which security problems can Wapiti test for?
Its modules include SQL injection, cross-site scripting, file disclosure, command execution, XXE, open redirects, CSRF, weak security headers, and dangerous files. It can also fingerprint web technologies and report related CVE information.
Can Wapiti scan login-protected pages and REST APIs?
Yes, Wapiti supports basic, digest, and NTLM authentication, login forms, cookies, and browser-based crawling. It can also scan REST APIs from an OpenAPI or Swagger definition.
What reports can Wapiti generate?
The project supports HTML, XML, JSON, TXT, CSV, and Markdown reports. Wapiti is released under the GPL-2.0 license and can be run on Windows through WSL.
explore Explore More
Reviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.