Vega
GUI-driven scanner and intercepting proxy in one.
What it does
Vega both crawls and actively scans your site for issues like SQL injection, cross-site scripting, and inadvertently disclosed sensitive information, and can also sit as a proxy to inspect the traffic between a browser and your server.
What data you get
A grouped list of alerts with severity, affected requests, and remediation notes, viewable in its interface or exported for a report.
Why it matters to your site
It surfaces the same class of code-level flaws as other active scanners while making the evidence easy to inspect request-by-request, which speeds up confirming and fixing a finding.
More in this category
Other general-purpose tools
OWASP ZAP
★ FeaturedThe most widely used open-source web application scanner.
Wapiti
Black-box scanner that audits your site by injecting real payloads.
Skipfish
High-speed active reconnaissance and security probe.