search
Get Started
search
Wapiti - Framework
zoom_in Click to enlarge

Wapiti

language

description Wapiti Overview

Wapiti is an open-source, automated website performance testing tool that simulates real browser usage to measure page load times and identify bottlenecks across various network conditions and devices.

help Wapiti FAQ

Is Wapiti a website performance or page-speed testing tool?

Wapiti is a black-box web application vulnerability scanner written in Python, not a page-speed measurement framework. It crawls deployed pages and forms, injects test payloads, and looks for errors or abnormal behavior.

Which security problems can Wapiti test for?

Its modules include SQL injection, cross-site scripting, file disclosure, command execution, XXE, open redirects, CSRF, weak security headers, and dangerous files. It can also fingerprint web technologies and report related CVE information.

Can Wapiti scan login-protected pages and REST APIs?

Yes, Wapiti supports basic, digest, and NTLM authentication, login forms, cookies, and browser-based crawling. It can also scan REST APIs from an OpenAPI or Swagger definition.

What reports can Wapiti generate?

The project supports HTML, XML, JSON, TXT, CSV, and Markdown reports. Wapiti is released under the GPL-2.0 license and can be run on Windows through WSL.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare