Sitelet https://github.com/Babybluess/Web-Security-Scanner
Skip to content

About

Automated Web/API Vulnerability Scanner — a Python CLI tool that probes web applications for common security vulnerabilities and generates a structured HTML report.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

web-security-scanner

Automated Web/API Vulnerability Scanner — a Python CLI tool that probes web applications for common security vulnerabilities and generates a structured HTML report.

Built as a lightweight alternative to repetitive Burp Suite manual checks, covering the most common OWASP Top 10 attack surfaces.


Features

Check What it detects
XSS Reflected XSS in form inputs and URL parameters (7 payloads)
SQLi Error-based and time-based blind SQL injection (forms + URL params)
Headers Missing/misconfigured security headers (CSP, HSTS, X-Frame-Options, etc.)
CORS Wildcard, reflected-origin, and null-origin CORS misconfigurations
JWT alg:none attack, weak secrets, missing expiry, sensitive data in payload
Traversal Path traversal in URL params + 30 common sensitive file exposures
CSRF Missing CSRF tokens on state-changing forms

Installation

git clone https://github.com/Babybluess/web-security-scanner
cd web-security-scanner
pip install -r requirements.txt

Usage

# Run all checks against a target
python scanner.py -u https://example.com

# Run specific checks only
python scanner.py -u https://example.com --checks xss sqli headers

# Custom output path and timeout
python scanner.py -u https://example.com --output reports/my_report.html --timeout 15

# Verbose mode (shows detail per finding in terminal)
python scanner.py -u https://example.com --verbose

# Print to stdout only, skip HTML report
python scanner.py -u https://example.com --no-report

Output

Terminal summary:

============================================================
  web-security-scanner
  Target : https://example.com
  Checks : xss, sqli, headers, cors, jwt, traversal, csrf
============================================================

  [1/7] Running XSS check...   ✓ 0 issue(s)
  [2/7] Running SQLI check...  ⚠ 1 issue(s)
  [3/7] Running HEADERS check... ⚠ 3 issue(s)
  ...

============================================================
  SCAN COMPLETE — 8 finding(s)
  HIGH: 1  MEDIUM: 3  LOW: 2  INFO: 2
============================================================
  🔴 [HIGH]   SQLi — Error-based SQL Injection in form field 'id'
  🟠 [MEDIUM] Headers — Missing Content-Security-Policy header
  ...

  📄 HTML report saved → reports/scan_report.html

An HTML report with colour-coded findings, evidence, and remediation steps is saved automatically.


Exit Codes

Code Meaning
0 Scan complete, no HIGH severity findings
1 One or more HIGH severity findings detected

Useful for CI/CD integration:

- name: Security scan
  run: python scanner.py -u ${{ env.STAGING_URL }} --no-report
  # Fails the pipeline if HIGH findings are found

Security Checks Detail

XSS (Cross-Site Scripting)

Injects 7 XSS payloads into every form input and URL parameter, then checks if the payload is reflected unescaped in the response.

SQL Injection

Tests with error-based payloads (checks response for SQL error signatures) and time-based blind payloads (measures response delay). Covers MySQL, PostgreSQL, MSSQL, Oracle, and SQLite error patterns.

Security Headers

Audits response headers against OWASP recommendations:

  • Required: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy
  • Dangerous: Server version disclosure, X-Powered-By

CORS

Sends requests with 4 different Origin values (evil.com, attacker.com, null, subdomain-confusion) and checks if they are reflected in Access-Control-Allow-Origin, especially combined with Allow-Credentials: true.

JWT

Scans page source, cookies, and response headers for JWT tokens, then tests each token for:

  • alg:none — signature bypass
  • Weak/common signing secrets (tested against a list of 14 common secrets)
  • Missing exp claim (no expiry)
  • Sensitive data (password, secret, ssn, etc.) in the payload

Directory Traversal

  • Probes 6 traversal payloads on URL parameters containing file/path-related names
  • Checks 30 common sensitive file paths (.env, .git/config, phpinfo.php, Actuator endpoints, etc.)

CSRF

Identifies POST/PUT/DELETE forms and checks for CSRF token inputs. Flags forms with no token and no CSRF-related response headers.


⚠️ Legal Notice

This tool is for authorised security testing only. Only scan systems you own or have explicit written permission to test. Unauthorised use is illegal.


Author

Hoang Minh Thang — github.com/Babybluess

About

Automated Web/API Vulnerability Scanner — a Python CLI tool that probes web applications for common security vulnerabilities and generates a structured HTML report.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages