- name
- web-security-scanner-pro
- description
- Advanced Python web security scanner with 49 modules, evasion engine, CVE database, and WAF bypass for penetration testing
- triggers
- ["scan website for vulnerabilities","run security audit on web application","test for SQL injection and XSS","check WordPress security issues","bypass WAF and scan protected site","detect web server vulnerabilities","generate security assessment report","perform penetration test on website"]
# Web Security Scanner Pro Skill
> Skill by [ara.so](https://ara.so) — Security Skills collection.
Expert skill for using Web Security Scanner Pro, a comprehensive Python-based web security scanner with 49 modules for vulnerability detection, WAF evasion, and automated security testing.
## What This Project Does
Web Security Scanner Pro (WSA Pro) is an open-source security testing tool that:
- **Scans for 49 vulnerability types** including XSS, SQLi, LFI, RFI, XXE, SSTI, CSRF, command injection
- **Tests CMS platforms** (WordPress with 9 modules, Joomla, Drupal)
- **Detects misconfigurations** in web servers (Apache, Nginx, IIS, LiteSpeed, Tomcat)
- **Identifies vulnerable software** via built-in CVE database (2024-2026)
- **Evades detection** with WAF bypass, user-agent rotation, rate limiting, proxy support
- **Generates professional reports** in HTML, PDF, Markdown, and JSON formats
- **Provides REST API** for automation and CI/CD integration
The scanner includes advanced SQL injection detection (error-based, boolean-blind, time-based blind, UNION-based) and can identify 9 different WAFs (Cloudflare, Sucuri, ModSecurity, etc.).
## Installation
### Prerequisites
```bash
# Requires Python 3.9+
python --version
# Install from GitHub
git clone https://github.com/miladrezanezhad/web-security-scanner-pro.git
cd web-security-scanner-pro
pip install -r requirements.txt
```
### Dependencies
The project requires these key Python packages:
- `requests` - HTTP client
- `beautifulsoup4` - HTML parsing
- `pyyaml` - Configuration
- `jinja2` - Report templates
- `reportlab` - PDF generation
- `flask` - REST API server
## Key Commands
### Basic Usage
```bash
# Interactive mode (menu-driven interface)
python main.py
# Quick scan (4 critical modules)
python main.py quick https://example.com
# Full scan (all 49 modules)
python main.py scan https://example.com
# Specific modules only
python main.py scan https://example.com --modules wordpress,xss,sqli,ssl
# Stealth mode for WAF-protected sites
python main.py scan https://example.com --mode stealth
# Aggressive mode (faster, more detectable)
python main.py scan https://example.com --mode aggressive
# Generate multiple report formats
python main.py scan https://example.com --format html pdf json markdown
# Use proxy
python main.py scan https://example.com --proxy http://127.0.0.1:8080
# Custom rate limiting
python main.py scan https://example.com --delay 2 --timeout 30
```
### Module Categories
```bash
# CMS scanning
python main.py scan https://example.com --modules wordpress,joomla,drupal
# Vulnerability testing
python main.py scan https://example.com --modules xss,sqli,lfi,xxe,ssti,csrf
# Server fingerprinting
python main.py scan https://example.com --modules apache,nginx,php,mysql
# Control panel detection
python main.py scan https://example.com --modules cpanel,directadmin,plesk
# SSL/TLS testing
python main.py scan https://example.com --modules ssl,headers
# API security
python main.py scan https://example.com --modules graphql,rest_api,jwt
```
## Configuration
### config.yaml Structure
```yaml
# Core settings
scanner:
timeout: 30
max_retries: 3
threads: 10
user_agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
# Evasion settings
evasion:
enabled: true
user_agent_rotation: true
random_delay: true
min_delay: 1
max_delay: 3
exponential_backoff: true
# Proxy configuration
proxy:
enabled: false
http: ""
https: ""
socks5: ""
tor: false
# Module configuration
modules:
enabled:
- wordpress
- xss
- sqli
- ssl
- headers
disabled:
- aggressive_fuzzing
# Report settings
reporting:
output_dir: "reports/output"
default_format: "html"
include_screenshots: false
# CVE database
database:
auto_update: true
update_interval: 7 # days
severity_filter: ["CRITICAL", "HIGH", "MEDIUM"]
```
### Environment Variables
```bash
# Set proxy via environment
export HTTP_PROXY="http://127.0.0.1:8080"
export HTTPS_PROXY="http://127.0.0.1:8080"
# API server configuration
export WSA_API_HOST="0.0.0.0"
export WSA_API_PORT="5000"
export WSA_API_KEY="your-secret-key-here"
# Database credentials (if needed)
export DB_HOST="localhost"
export DB_USER="scanner"
export DB_PASS="${DB_PASSWORD}"
```
## Python API Usage
### Programmatic Scanning
```python
from core.scanner import SecurityScanner
from core.browser import StealthBrowser
from core.evasion import EvasionEngine
# Initialize scanner
scanner = SecurityScanner(
target="https://example.com",
modules=["wordpress", "xss", "sqli"],
mode="stealth"
)
# Configure evasion
scanner.evasion = EvasionEngine(
user_agent_rotation=True,
random_delay=True,
waf_detection=True
)
# Run scan
results = scanner.scan()
# Access findings
for finding in results.get_findings():
print(f"{finding.severity}: {finding.title}")
print(f" Module: {finding.module}")
print(f" Description: {finding.description}")
print(f" Remediation: {finding.remediation}")
```
### Custom Module Development
```python
from modules.base import BaseModule
class CustomScanModule(BaseModule):
"""Custom security scanning module."""
def __init__(self, browser):
super().__init__(browser)
self.name = "custom_scan"
self.description = "Custom vulnerability detection"
def run(self, target):
"""Execute custom scan logic."""
findings = []
# Make HTTP request
response = self.browser.get(target)
# Check for vulnerability
if self._check_vulnerability(response):
findings.append({
"severity": "HIGH",
"title": "Custom Vulnerability Detected",
"description": "Found custom security issue",
"url": target,
"evidence": response.text[:200],
"remediation": "Apply custom fix"
})
return findings
def _check_vulnerability(self, response):
"""Custom vulnerability detection logic."""
return "vulnerable_pattern" in response.text.lower()
# Register and use custom module
scanner.register_module(CustomScanModule)
```
### Advanced SQL Injection Testing
```python
from modules.vulnerabilities.sqli import SQLInjectionScanner
# Initialize SQLi scanner
sqli_scanner = SQLInjectionScanner(browser)
# Test specific parameter
result = sqli_scanner.test_parameter(
url="https://example.com/page.php",
parameter="id",
value="1"
)
if result.vulnerable:
print(f"SQLi Type: {result.injection_type}") # error, boolean, time, union
print(f"Database: {result.database_type}") # mysql, postgresql, mssql
print(f"Payload: {result.payload}")
print(f"Evidence: {result.evidence}")
# Advanced time-based detection
time_result = sqli_scanner.test_time_based(
url="https://example.com/search",
parameter="q",
delay=5 # seconds
)
```
### WAF Detection and Bypass
```python
from core.evasion import EvasionEngine
evasion = EvasionEngine()
# Detect WAF
waf_info = evasion.detect_waf("https://example.com")
if waf_info["detected"]:
print(f"WAF Detected: {waf_info['name']}")
print(f"Confidence: {waf_info['confidence']}")
# Apply WAF-specific bypass techniques
evasion.apply_bypass_techniques(waf_info['name'])
# Test bypass effectiveness
bypass_success = evasion.test_bypass(
url="https://example.com",
payload="<script>alert(1)</script>"
)
# Supported WAFs:
# - Cloudflare
# - Sucuri
# - Wordfence
# - AWS WAF
# - ModSecurity
# - Akamai
# - Imperva
# - F5 BIG-IP
# - Barracuda
```
### Report Generation
```python
from core.reporter import ReportGenerator
# Initialize reporter
reporter = ReportGenerator(scan_results)
# Generate HTML report with charts
html_report = reporter.generate_html(
output_file="reports/output/scan_report.html",
include_charts=True,
include_screenshots=False
)
# Generate PDF report
pdf_report = reporter.generate_pdf(
output_file="reports/output/scan_report.pdf",
company_name="Security Corp",
tester_name="John Doe"
)
# Generate JSON for automation
json_report = reporter.generate_json(
output_file="reports/output/scan_report.json",
pretty_print=True
)
# Markdown for GitHub
md_report = reporter.generate_markdown(
output_file="reports/output/scan_report.md"
)
```
### CVE Database Queries
```python
from core.database import VulnerabilityDatabase
# Initialize CVE database
cve_db = VulnerabilityDatabase()
# Search for WordPress vulnerabilities
wp_vulns = cve_db.search_by_software(
software="WordPress",
version="6.4.2"
)
for vuln in wp_vulns:
print(f"CVE: {vuln.cve_id}")
print(f"CVSS: {vuln.cvss_score}")
print(f"Severity: {vuln.severity}")
print(f"Description: {vuln.description}")
# Search by CVE ID
cve_info = cve_db.get_by_cve("CVE-2024-12345")
# Filter by severity
critical_vulns = cve_db.filter_by_severity("CRITICAL")
# Update database
cve_db.update_database()
```
## REST API Usage
### Start API Server
```bash
# Start REST API server
python -m core.api --host 0.0.0.0 --port 5000
# With authentication
export WSA_API_KEY="your-secret-key"
python -m core.api --host 0.0.0.0 --port 5000 --auth
```
### API Endpoints
```python
import requests
API_BASE = "http://localhost:5000/api/v1"
API_KEY = os.getenv("WSA_API_KEY")
headers = {"X-API-Key": API_KEY}
# Start new scan
response = requests.post(
f"{API_BASE}/scan",
headers=headers,
json={
"target": "https://example.com",
"modules": ["wordpress", "xss", "sqli"],
"mode": "stealth",
"report_format": ["html", "json"]
}
)
scan_id = response.json()["scan_id"]
# Check scan status
status = requests.get(
f"{API_BASE}/scan/{scan_id}/status",
headers=headers
)
print(status.json())
# Get scan results
results = requests.get(
f"{API_BASE}/scan/{scan_id}/results",
headers=headers
)
# Download report
report = requests.get(
f"{API_BASE}/scan/{scan_id}/report?format=html",
headers=headers
)
# List available modules
modules = requests.get(
f"{API_BASE}/modules",
headers=headers
)
# Get CVE information
cve_info = requests.get(
f"{API_BASE}/cve/CVE-2024-12345",
headers=headers
)
```
## Common Patterns
### WordPress Security Audit
```python
from core.scanner import SecurityScanner
# Comprehensive WordPress scan
scanner = SecurityScanner(
target="https://wordpress-site.com",
modules=[
"wordpress_version",
"wordpress_plugins",
"wordpress_themes",
"wordpress_users",
"wordpress_xmlrpc",
"wordpress_readme",
"wordpress_debug",
"wordpress_directory_listing",
"wordpress_config_backup"
]
)
results = scanner.scan()
# Check for specific WordPress issues
if results.has_finding("wordpress_xmlrpc"):
print("XML-RPC enabled - potential brute force target")
if results.has_finding("wordpress_debug"):
print("Debug mode enabled - information disclosure")
# Export WordPress-specific report
results.export_wordpress_report("wp_audit.pdf")
```
### Stealth Scanning for Protected Sites
```python
from core.scanner import SecurityScanner
from core.evasion import EvasionEngine
# Configure stealth mode
Auf GitHub ansehen