{"repo":"chushuai/wscan","free":true,"listed":false,"github":"https://github.com/chushuai/wscan","clone":"git clone https://github.com/chushuai/wscan.git","description":"Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.","language":"Go","stars":710,"topics":["crawler","passive-vulnerability-scanner","poc","sql-injection","vulnerability-scanner","webscan","chromedp","headless","cel-go","martian"],"license":null,"category":"security-tools","readme_excerpt":"中文 wscan A web security scanner for active, passive, and AI-driven penetration testing. wscan covers the full OWASP web vulnerability landscape — XSS, SQLi, RCE, path traversal, SSRF, XXE, file upload, and more — plus component fingerprinting, sensitive-info detection, and a plugin engine that runs Nuclei / Xray / Goby POCs. It ships with a browser-based WebUI for managing scans, a built-in reverse-connect platform for blind vulnerabilities, and an AI agent mode that drives the scanner autonomously via the local Claude CLI. ⚠️ Legal : Scanning a target without prior authorization is illegal. wscan is intended for authorized security testing only. Read and agree to the License before use. --- Features at a glance - WebUI — manage targets, scans, and results in a browser; results persist across restarts; IM push notifications (Feishu/Lark, WeCom, DingTalk). - Active & passive scanning — crawl-then-scan (static or headless-browser crawler), single-URL / URL-file / raw-request modes, and MITM-based passive listening. - 28+ built-in detection plugins — semantic XSS, SQLi (error/boolean/time-blind), command injection, path traversal, XXE, SSRF, file upload, brute-force, JSONP, redirect, CRLF, baseline, plus Struts2 / Shiro / Fastjson / ThinkPHP / XStream component checks. - POC engine — runs Nuclei, Xray, and Goby POCs from one directory, with configurable detection depth. - Custom FUZZ & WAF testing — YAML-defined payloads with encoders, placeholders, and CEL/regex verification; t","default_branch":null,"files":null,"tree":[],"storefront":"/r/chushuai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/chushuai/wscan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}