Wapiti review
A free, self-hosted DAST scanner with broad checks and flexible scan controls.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
Wapiti is a command-line, open-source dynamic application security testing tool for developers, security professionals, and system administrators. It performs black-box testing against deployed web applications by crawling sites, discovering URLs, forms, and inputs, then injecting payloads to identify weaknesses. Wapiti runs on Linux, macOS, and Windows, uses a self-hosted deployment model, and is distributed under GPLv2. It fits small teams that want a free scanner they can run locally and configure around their own applications.
Its strongest area is coverage across common web-application testing workflows. Wapiti supports HTTP authentication and login-form authentication, REST API scanning from OpenAPI or Swagger definitions, headless Firefox, and browser-assisted crawling. Detection includes SQL injection, cross-site scripting, XXE, SSRF, CSRF, and command injection, along with security-header and cookie-flag checks. Teams can configure attack modules and crawling scope, while session storage supports suspending and resuming scans. These controls make it suitable for applications that need more than unauthenticated URL discovery.
Reporting and workflow flexibility also matter. Results can be produced in HTML, XML, JSON, TXT, CSV, and Markdown, which supports different review and automation needs. Wapiti can also fit self-hosted CI/CD environments, and its free, open-source model avoids commercial tier selection. The trade-off is its command-line focus: teams looking for a vendor-hosted SaaS interface or a graphical workflow should choose an alternative. Wapiti is a strong fit for technically comfortable teams that value local control, configurable scans, and broad web vulnerability checks over a managed service experience.
Wapiti pros and cons
- Where it wins
- Free and open source with self-hosted deployment
- Scans authenticated sites, REST APIs, and browser-driven flows
- Exports reports in HTML, JSON, XML, TXT, CSV, and Markdown
- Where it doesn't
- Command-line operation may not suit teams seeking a graphical interface
- Scanning is focused on deployed web applications and APIs
- No commercial plan tiers or vendor-hosted service option
Wapiti fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update