Wapiti is a Python scanner for auditing deployed websites and web applications for vulnerabilities. It crawls links, forms, and scripts and tests them with payloads rather than examining source code. Its listed checks cover SQL and XPath injection, cross-site scripting, file disclosure, command execution, XXE, SSRF, and open redirects. It can scan REST APIs using an OpenAPI (Swagger) file and supports authentication through Basic, Digest, or NTLM, login forms, imported browser cookies, or custom Python code. Users can set scan scope, crawler limits, HTTP headers, and HTTP, HTTPS, or SOCKS5 proxies. Scan sessions can be paused and resumed using SQLite databases. Reports are available in HTML, XML, JSON, TXT, CSV, and Markdown. Installation is offered with pip install wapiti3, and the README lists Python 3.12, 3.13, or 3.14 as requirements; Windows use is through WSL. Wapiti is free under GNU GPL version 2. The project warns that scans may cause malfunctions, crashes, or data loss, and requires the target owner's consent.
Who it is for
Wapiti suits website and application administrators who need to scan deployed targets, including authenticated sites or REST APIs. It is for use where the target owner's consent has been obtained and Python 3.12, 3.13, or 3.14 is available.
What is good
- Free under GNU GPL version 2.
- Checks a broad list of vulnerability types.
- Can scan REST APIs from an OpenAPI file.
- Supports multiple authentication methods and proxies.
- Exports reports in six listed formats.
What to know first
- Requires Python 3.12, 3.13, or 3.14.
- Windows use is through WSL.
- Scans may cause crashes or data loss.
- Requires target owner's consent.
Verdict
Wapiti offers configurable scans, authentication options, and multiple report formats for deployed web applications and REST APIs. Its requirements and the risk of disrupting a target make consent and careful scope configuration important before a scan.
Wapiti plans and pricing
All plansCompared on web application security scanners
- Free plan
- Yes
- Deployment
- on-premise
- Authenticated scans
- Yes
- JavaScript crawling
- Yes
- API scanning
- Yes


