Wapiti
Wapiti is an open-source black-box web application vulnerability scanner used in penetration testing to probe live sites for common flaws without source-code access. It targets deployed HTTP applications and is best suited for testers who need lightweight, repeatable web attack surface validation rather than full red-team adversary emulation. Its market position is that of a classic web pentest utility, not a broad red-team platform. It is especially useful for security researchers, consultants, and administrators auditing public-facing web apps.
Visit websiteAsk about pricing, alternatives, or if Wapiti is right for you.
The Picari read
Wapiti is an open-source web vulnerability scanner for penetration testing of live HTTP applications. Its main value is black-box crawling and payload injection against deployed sites, making it a fit for consultants and internal testers who need repeatable validation of web inputs and exposed endpoints.
- Organizations needing a lightweight, open-source black-box scanner for web application vulnerability detection.
- Pre-deployment web application vulnerability scanning
- Continuous monitoring of web application security posture
- Ad-hoc security audits of web properties
- Identifying common web application flaws like XSS and SQL injection
Product catalogue
Wapiti pricing and integrations
For Wapiti integration and pricing details, ask Picari. Start a briefing with your question, such as whether it connects to your SIEM, identity provider and ticketing stack, or how it is priced at your seat count and data volume.
Unverified profile
This profile hasn't been verified by Wapiti yet. Information may be incomplete.
Are you from Wapiti? Verify this profileProfile last updated on 6 September 2026 by Picari.