Arachni
Feature-rich scanner that understands modern, JavaScript-heavy apps.
What it does
Arachni performs a deep active scan with a browser-based crawler that can handle dynamic, single-page style applications, testing for a wide range of injection, session, and configuration flaws while adapting its checks as it learns your app.
What data you get
Detailed, low-noise findings with severity, proof, and remediation guidance, delivered as HTML, JSON, XML, or other report formats.
Why it matters to your site
Because it drives a real browser, it reaches parts of a modern app that simpler crawlers miss — so the results reflect what an attacker interacting with your live interface would actually find.
More in this category
Other general-purpose tools
OWASP ZAP
★ FeaturedThe most widely used open-source web application scanner.
Wapiti
Black-box scanner that audits your site by injecting real payloads.
Skipfish
High-speed active reconnaissance and security probe.