Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Wapiti review

Free#23 of 26 in Dynamic Application Security Testing Software

A free, self-hosted DAST scanner with broad checks and flexible scan controls.

7.2/10Editor score
Wapiti7.2 Visit Wapiti

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Wapiti is a command-line, open-source dynamic application security testing tool for developers, security professionals, and system administrators. It performs black-box testing against deployed web applications by crawling sites, discovering URLs, forms, and inputs, then injecting payloads to identify weaknesses. Wapiti runs on Linux, macOS, and Windows, uses a self-hosted deployment model, and is distributed under GPLv2. It fits small teams that want a free scanner they can run locally and configure around their own applications.

Its strongest area is coverage across common web-application testing workflows. Wapiti supports HTTP authentication and login-form authentication, REST API scanning from OpenAPI or Swagger definitions, headless Firefox, and browser-assisted crawling. Detection includes SQL injection, cross-site scripting, XXE, SSRF, CSRF, and command injection, along with security-header and cookie-flag checks. Teams can configure attack modules and crawling scope, while session storage supports suspending and resuming scans. These controls make it suitable for applications that need more than unauthenticated URL discovery.

Reporting and workflow flexibility also matter. Results can be produced in HTML, XML, JSON, TXT, CSV, and Markdown, which supports different review and automation needs. Wapiti can also fit self-hosted CI/CD environments, and its free, open-source model avoids commercial tier selection. The trade-off is its command-line focus: teams looking for a vendor-hosted SaaS interface or a graphical workflow should choose an alternative. Wapiti is a strong fit for technically comfortable teams that value local control, configurable scans, and broad web vulnerability checks over a managed service experience.

Wapiti pros and cons

  • Where it wins
    • Free and open source with self-hosted deployment
    • Scans authenticated sites, REST APIs, and browser-driven flows
    • Exports reports in HTML, JSON, XML, TXT, CSV, and Markdown
  • Where it doesn't
    • Command-line operation may not suit teams seeking a graphical interface
    • Scanning is focused on deployed web applications and APIs
    • No commercial plan tiers or vendor-hosted service option

Wapiti fact sheet, pricing and score →

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update