Wapiti allows you to audit the security of your web applications. Wapiti is a command line tool.
Cost / License
- Free
- Open Source
Platforms
- Windows
- Linux
Apps similar to Acunetix include SiteOne Crawler, which is free and open source. Other options are Burp Suite, OpenVAS, Zed Attack Proxy (ZAP) and Nessus. You're spoiled for choice with Vulnerability Scanners like Acunetix: we list more than 50 alternatives for the web, Linux, Windows, self-hosting and Mac.
Wapiti allows you to audit the security of your web applications. Wapiti is a command line tool.
Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.

Test your website like a real attacker would. Nautillo Pro finds account takeover risks, API exposure, broken access control, and AI security flaws before users and hackers do.




Unified application security platform — 12 scanners including SAST, DAST, SCA, and pen-testing in one on-premise deployment. Replaces your entire AppSec stack.
ShipSafe is a free online website safety checker that helps users quickly analyze whether a website is safe or potentially risky. By entering a domain or URL, ShipSafe provides a trust score, security insights, and reputation indicators that help users avoid scams, phishing...


A fully automated, active web application security reconnaissance tool. Key features: High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.



Defense, driven by a fleet of AI agents. Axeploit can automatically create multiple accounts. It operates & attacks with real contact details, just like a hacker.



Free online vulnerability scanner. It has been working since 2016 and has two modes: quick and normal. The service is quite easy to use and does not require registration. You need to enter your website URL and email to receive a security report.

DefenseCode WebStrike is a DAST (Dynamic Application Security Testing, BlackBox Testing) solution for comprehensive security audits of active web applications (websites).


📈 Measure and control your application security state; 🔎 Scan your code, containers, web and mobile applications; 🔥 Remove duplicates, validate results, and create Jira tasks in seconds; 🕜 Save your engineers time and automate your processes; ? Self-hosted.



Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies.