Wapiti

Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.5

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

Wapiti is a Python scanner for auditing deployed websites and web applications for vulnerabilities. It crawls links, forms, and scripts and tests them with payloads rather than examining source code. Its listed checks cover SQL and XPath injection, cross-site scripting, file disclosure, command execution, XXE, SSRF, and open redirects. It can scan REST APIs using an OpenAPI (Swagger) file and supports authentication through Basic, Digest, or NTLM, login forms, imported browser cookies, or custom Python code. Users can set scan scope, crawler limits, HTTP headers, and HTTP, HTTPS, or SOCKS5 proxies. Scan sessions can be paused and resumed using SQLite databases. Reports are available in HTML, XML, JSON, TXT, CSV, and Markdown. Installation is offered with pip install wapiti3, and the README lists Python 3.12, 3.13, or 3.14 as requirements; Windows use is through WSL. Wapiti is free under GNU GPL version 2. The project warns that scans may cause malfunctions, crashes, or data loss, and requires the target owner's consent.

Who it is for

Wapiti suits website and application administrators who need to scan deployed targets, including authenticated sites or REST APIs. It is for use where the target owner's consent has been obtained and Python 3.12, 3.13, or 3.14 is available.

What is good

  • Free under GNU GPL version 2.
  • Checks a broad list of vulnerability types.
  • Can scan REST APIs from an OpenAPI file.
  • Supports multiple authentication methods and proxies.
  • Exports reports in six listed formats.

What to know first

  • Requires Python 3.12, 3.13, or 3.14.
  • Windows use is through WSL.
  • Scans may cause crashes or data loss.
  • Requires target owner's consent.

Verdict

Wapiti offers configurable scans, authentication options, and multiple report formats for deployed web applications and REST APIs. Its requirements and the risk of disrupting a target make consent and careful scope configuration important before a scan.

Wapiti plans and pricing

All plans
Free and open-source Free GNU GPL version 2 github.com · 3 Oct 2026

Compared on web application security scanners

Free plan
Yes
Deployment
on-premise
Authenticated scans
Yes
JavaScript crawling
Yes
API scanning
Yes

Best Wapiti alternatives

See all 20