Automated web vulnerability scanner for identifying common security weaknesses. This tool helps developers and security auditors find vulnerabilities like SQL injection, XSS, and misconfigured headers.
- SQL Injection detection
- Cross-Site Scripting (XSS) scanning
- Security header analysis
- Directory brute-forcing
- Automated report generation
git clone https://github.com/Prem2868/web-vulnerability-scanner.git
cd web-vulnerability-scanner
pip install -r requirements.txtUse this tool only against systems you own or are explicitly authorized to test. The scanner uses low-volume heuristics and does not prove exploitability.
python src/scanner.py https://example.test/item?id=1 --parameter id --timeout 10 --confirm-authorizedThe SQL check reports responses containing common database-error markers. Reflected text is not automatically an exploitable XSS finding; validate context, output encoding, and application behavior manually.
- Language: Python
- Libraries: Requests, BeautifulSoup4, Selenium
- Platform: Cross-platform
Do not scan unauthorized targets, run denial-of-service tests, or include sensitive target details in issues and logs. Prefer local fixtures and intentionally vulnerable training applications for development.
Contributions are welcome! Please follow the standard GitHub workflow for PRs and include tests for new detection logic.
This project is licensed under the MIT License - see the LICENSE file for details.
Author: Pramod Jogdand | https://github.com/Prem2868