Automated Web/API Vulnerability Scanner — a Python CLI tool that probes web applications for common security vulnerabilities and generates a structured HTML report.
Built as a lightweight alternative to repetitive Burp Suite manual checks, covering the most common OWASP Top 10 attack surfaces.
| Check | What it detects |
|---|---|
| XSS | Reflected XSS in form inputs and URL parameters (7 payloads) |
| SQLi | Error-based and time-based blind SQL injection (forms + URL params) |
| Headers | Missing/misconfigured security headers (CSP, HSTS, X-Frame-Options, etc.) |
| CORS | Wildcard, reflected-origin, and null-origin CORS misconfigurations |
| JWT | alg:none attack, weak secrets, missing expiry, sensitive data in payload |
| Traversal | Path traversal in URL params + 30 common sensitive file exposures |
| CSRF | Missing CSRF tokens on state-changing forms |
git clone https://github.com/Babybluess/web-security-scanner
cd web-security-scanner
pip install -r requirements.txt# Run all checks against a target
python scanner.py -u https://example.com
# Run specific checks only
python scanner.py -u https://example.com --checks xss sqli headers
# Custom output path and timeout
python scanner.py -u https://example.com --output reports/my_report.html --timeout 15
# Verbose mode (shows detail per finding in terminal)
python scanner.py -u https://example.com --verbose
# Print to stdout only, skip HTML report
python scanner.py -u https://example.com --no-reportTerminal summary:
============================================================
web-security-scanner
Target : https://example.com
Checks : xss, sqli, headers, cors, jwt, traversal, csrf
============================================================
[1/7] Running XSS check... ✓ 0 issue(s)
[2/7] Running SQLI check... ⚠ 1 issue(s)
[3/7] Running HEADERS check... ⚠ 3 issue(s)
...
============================================================
SCAN COMPLETE — 8 finding(s)
HIGH: 1 MEDIUM: 3 LOW: 2 INFO: 2
============================================================
🔴 [HIGH] SQLi — Error-based SQL Injection in form field 'id'
🟠 [MEDIUM] Headers — Missing Content-Security-Policy header
...
📄 HTML report saved → reports/scan_report.html
An HTML report with colour-coded findings, evidence, and remediation steps is saved automatically.
| Code | Meaning |
|---|---|
0 |
Scan complete, no HIGH severity findings |
1 |
One or more HIGH severity findings detected |
Useful for CI/CD integration:
- name: Security scan
run: python scanner.py -u ${{ env.STAGING_URL }} --no-report
# Fails the pipeline if HIGH findings are foundInjects 7 XSS payloads into every form input and URL parameter, then checks if the payload is reflected unescaped in the response.
Tests with error-based payloads (checks response for SQL error signatures) and time-based blind payloads (measures response delay). Covers MySQL, PostgreSQL, MSSQL, Oracle, and SQLite error patterns.
Audits response headers against OWASP recommendations:
- Required: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy
- Dangerous: Server version disclosure, X-Powered-By
Sends requests with 4 different Origin values (evil.com, attacker.com, null, subdomain-confusion) and checks if they are reflected in Access-Control-Allow-Origin, especially combined with Allow-Credentials: true.
Scans page source, cookies, and response headers for JWT tokens, then tests each token for:
alg:none— signature bypass- Weak/common signing secrets (tested against a list of 14 common secrets)
- Missing
expclaim (no expiry) - Sensitive data (password, secret, ssn, etc.) in the payload
- Probes 6 traversal payloads on URL parameters containing file/path-related names
- Checks 30 common sensitive file paths (
.env,.git/config,phpinfo.php, Actuator endpoints, etc.)
Identifies POST/PUT/DELETE forms and checks for CSRF token inputs. Flags forms with no token and no CSRF-related response headers.
This tool is for authorised security testing only. Only scan systems you own or have explicit written permission to test. Unauthorised use is illegal.
Hoang Minh Thang — github.com/Babybluess