Nikto
Web Server Scanner.
Overview
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6700 potentially dangerous files/programs, checks for outdated versions of over 1250 servers, and version specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software.
✨ Key Features
- Scans for over 6700 dangerous files/CGIs
- Checks for outdated server software
- Identifies server configuration issues
- SSL certificate scanning
- Proxy support
🎯 Key Differentiators
- Focus on web server security
- Large database of known vulnerabilities and misconfigurations
- Fast and easy to use for quick scans
Unique Value: Provides a quick and easy way to scan web servers for a wide range of common security vulnerabilities.
🎯 Use Cases (3)
✅ Best For
- Quickly identifying common security issues on a web server
- Getting a baseline security assessment of a web server
💡 Check With Vendor
Verify these considerations match your specific requirements:
- In-depth web application scanning (it's not a DAST)
- Exploitation
🏆 Alternatives
More focused on web server scanning than general-purpose network scanners like Nmap.
💻 Platforms
✅ Offline Mode Available
💰 Pricing
Free tier: Nikto is completely free and open-source.
🔄 Similar Tools in Penetration Testing Tools
Metasploit
An open-source framework for developing, testing, and executing exploit code against a remote target...
Burp Suite
An integrated platform for performing security testing of web applications....
Nmap
A free and open-source utility for network discovery and security auditing....
Wireshark
A free and open-source packet analyzer used for network troubleshooting and analysis....
Nessus
A proprietary vulnerability scanner developed by Tenable, Inc....
Acunetix
An automated web application security testing tool that audits your web applications by checking for...