The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




There are many alternatives to Nikto for Linux if you are looking for a replacement. The best Linux alternative is Zed Attack Proxy (ZAP), which is both free and Open Source. If that doesn't suit you, our users have ranked more than 10 alternatives to Nikto and seven of them are available for Linux so hopefully you can find a suitable replacement. Other interesting Linux alternatives to Nikto are Lonkero, wapiti, w3af and nuclei.
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




Lonkero is a high-performance web vulnerability scanner built in Rust for penetration testers and bug bounty hunters who are tired of slow, bloated tools that generate hundreds of false positives.


Wapiti allows you to audit the security of your web applications. Wapiti is a command line tool.



Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.

Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies.
A fully automated, active web application security reconnaissance tool. Key features: High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.


It takes up more time to process in comparison.