Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Wapiti

Free#23 of 26 in Dynamic Application Security Testing Software

Wapiti: A free, self-hosted DAST scanner with broad checks and flexible scan controls. Ranked #23 of 26 in Dynamic Application Security Testing Software by our editors (7.2/10); pricing: Free plan; best for small teams wanting free, straightforward DAST.

7.2/10Editor score
Wapiti7.2 Visit Wapiti

At a glance

  • Editor score
    7.2 / 10
  • Pricing
    Free plan
  • Best for
    Small teams wanting free, straightforward DAST
  • Free plan
    Yes
  • Paid from
    None
  • Authenticated scanning
    Yes
  • Facts checked
    22 Sep 2026
Wapiti screenshot
  • Where it wins

    • Free and open source with self-hosted deployment
    • Scans authenticated sites, REST APIs, and browser-driven flows
    • Exports reports in HTML, JSON, XML, TXT, CSV, and Markdown
  • Where it doesn't

    • Command-line operation may not suit teams seeking a graphical interface
    • Scanning is focused on deployed web applications and APIs
    • No commercial plan tiers or vendor-hosted service option

Our verdict on Wapiti

Wapiti is a command-line, open-source dynamic application security testing tool for developers, security professionals, and system administrators. It performs black-box testing against deployed web applications by crawling sites, discovering URLs, forms, and inputs, then injecting payloads to identify weaknesses. Wapiti runs on Linux, macOS, and Windows, uses a self-hosted deployment model, and is distributed under GPLv2. It fits small teams that want a free scanner they can run locally and configure around their own applications.

Its strongest area is coverage across common web-application testing workflows. Wapiti supports HTTP authentication and login-form authentication, REST API scanning from OpenAPI or Swagger definitions, headless Firefox, and browser-assisted crawling. Detection includes SQL injection, cross-site scripting, XXE, SSRF, CSRF, and command injection, along with security-header and cookie-flag checks. Teams can configure attack modules and crawling scope, while session storage supports suspending and resuming scans. These controls make it suitable for applications that need more than unauthenticated URL discovery.

Reporting and workflow flexibility also matter. Results can be produced in HTML, XML, JSON, TXT, CSV, and Markdown, which supports different review and automation needs. Wapiti can also fit self-hosted CI/CD environments, and its free, open-source model avoids commercial tier selection. The trade-off is its command-line focus: teams looking for a vendor-hosted SaaS interface or a graphical workflow should choose an alternative. Wapiti is a strong fit for technically comfortable teams that value local control, configurable scans, and broad web vulnerability checks over a managed service experience.

Wapiti pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on wapiti-scanner.github.io

Wapiti fact sheet

Free planYes
Paid fromNone
Authenticated scanningYes
API testingYes
Browser-based scanningYes
CI/CD integrationNot verified
Deployment modelSelf_hosted
Included scan targetsNot verified
DeploymentSelf-hosted
PlatformsWindows, macOS, Linux
SupportCommunity, Docs
Built forSolo, Small business, Mid-market (editorial estimate)
PricingFree plan
Websitewapiti-scanner.github.io
Facts checked22 Sep 2026

Alternatives to Wapiti

See all Wapiti alternatives →

Used Wapiti? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used Wapiti for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — Wapiti 7.2/10

Wapiti is listed in our Dynamic Application Security Testing Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/wapiti/"><img src="https://www.itechguides.com/best/badge/wapiti.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update