web-security-scanner-pro
Installation
SKILL.md
Web Security Scanner Pro Skill
Skill by ara.so — Security Skills collection.
Expert skill for using Web Security Scanner Pro, a comprehensive Python-based web security scanner with 49 modules for vulnerability detection, WAF evasion, and automated security testing.
What This Project Does
Web Security Scanner Pro (WSA Pro) is an open-source security testing tool that:
- Scans for 49 vulnerability types including XSS, SQLi, LFI, RFI, XXE, SSTI, CSRF, command injection
- Tests CMS platforms (WordPress with 9 modules, Joomla, Drupal)
- Detects misconfigurations in web servers (Apache, Nginx, IIS, LiteSpeed, Tomcat)
- Identifies vulnerable software via built-in CVE database (2024-2026)
- Evades detection with WAF bypass, user-agent rotation, rate limiting, proxy support
- Generates professional reports in HTML, PDF, Markdown, and JSON formats
- Provides REST API for automation and CI/CD integration
The scanner includes advanced SQL injection detection (error-based, boolean-blind, time-based blind, UNION-based) and can identify 9 different WAFs (Cloudflare, Sucuri, ModSecurity, etc.).