LeakIX

LeakIX

LeakIX is an open-source web vulnerability scanner that helps identify security weaknesses in web applications. It can detect SQL injections, XSS, insecure cookies, and other vulnerabilities.
LeakIX image
web-security vulnerability-scanning web-application-security open-source

LeakIX: Open-Source Web Vulnerability Scanner

An open-source tool to identify security weaknesses in web applications, detecting SQL injections, XSS, insecure cookies, and other vulnerabilities.

What is LeakIX?

LeakIX is an open-source web application security scanner designed to help developers and security professionals identify vulnerabilities in their web apps. It can automatically crawl web applications and APIs to detect common security issues like:

  • SQL injection
  • Cross-site scripting (XSS)
  • Insecure cookies
  • Command injection
  • Path traversal
  • Insecure headers
  • And more

Some key features of LeakIX include:

  • Automatic crawling and scanning of web apps
  • Custom scan profiles for focused security tests
  • Powerful fuzzing engine for finding unknown flaws
  • Extensive reporting on found vulnerabilities
  • Built-in exploit modules
  • Easy setup as a Docker container

LeakIX is written in Golang, which makes it fast and portable across platforms. It can scale to test large, complex web applications thanks to its modular architecture. The project is open source under the Apache 2.0 license, with an active community contributing plugins and fixes.

LeakIX Features

Features

  1. Scans for SQL injections, XSS, insecure cookies, and other vulnerabilities
  2. Open-source and free to use
  3. Easy to install and configure
  4. Command-line interface and web UI available
  5. Automatic crawling of web application
  6. Detailed vulnerability reports
  7. False positive reduction via proof-of-concept verification
  8. Extensible via plugins

Pricing

  • Open Source

Pros

Free and open-source

Easy to use

Good detection of common vulnerabilities

Active development and community support

Cons

Limited scanning capabilities compared to commercial tools

Prone to false positives

Lacks user and access management features

Minimal reporting customization options


The Best LeakIX Alternatives

Top Security & Privacy and Vulnerability Scanner and other similar apps like LeakIX

Here are some alternatives to LeakIX:

Suggest an alternative ❐

Criminal IP icon

Criminal IP

Criminal IP is an investigative software designed specifically for cybersecurity professionals and law enforcement agencies to trace IP addresses and gather actionable intelligence on cybercriminals. It integrates seamlessly with other security solutions to accelerate investigations.Key features of Criminal IP include:IP address tracking - Identify location, ISP, hosting provider, and other...
Criminal IP image