What it does
Wapiti works in two phases. First it crawls the target, following links and forms to build a list of URLs, parameters, form fields and upload points. Then it attacks that list, injecting payloads into each input and inspecting the response for evidence of a vulnerability. It never looks at source code, so it behaves the same way against any stack.
Attacks are organized as selectable modules, and choosing them is how you control scope and runtime. Modules cover SQL injection including blind variants, cross-site scripting, command execution, file disclosure and path traversal, server-side request forgery, XML external entity processing, open redirects, misconfigured headers, exposed backup and configuration files, and known-vulnerable component fingerprints. Detection of blind classes is supported by an out-of-band endpoint, which is how it catches injection where the response body reveals nothing. Authenticated scanning is available through supplied credentials, a login form description or an imported session, and reports are written to HTML, JSON, XML or plain text. Everything is driven from flags on one command, with no GUI and no server component.
Where it fits
Wapiti fits an operator's workflow or a simple automation job. A tester runs it early against a target for broad coverage of the common classes before doing manual work, and a small team can schedule it against staging and parse the JSON output. It has no console, no findings database and no ticket integration, so anything beyond a single scan and a report is something you build around it. You need reachability, authorization and, behind a login, a session configuration.
Strengths
- Installs and runs with almost no setup, which makes it easy to put in a script or a container.
- Module selection gives precise control over which attacks run, so you can keep scans fast and targeted.
- Out-of-band detection support catches blind injection classes that pure response inspection misses.
- Machine-readable output makes it straightforward to feed into your own pipeline or dashboard.
Limitations
- The crawler does not execute JavaScript in the way a browser-driven scanner does, so single-page applications are covered poorly.
- No result management at all: no history, no deduplication across runs, no triage workflow.
- Like any injection-focused scanner it says nothing about authorization or business logic flaws.
- False positives are a real part of the output and reviewing them is on you.
Who it suits
A good fit for penetration testers wanting a fast first pass, for lab use, and for small teams comfortable wiring a command line tool into their own automation. Not the right choice for an organization that needs portfolio management and triage tooling, or for testing a heavily client-side application.
Used Wapiti? Recommend it under your own name and title.
Recommend this tool