โ–ฒ RC

Web Vuln
Sidekick

// WVS

Web application vulnerability scanning sidekick. Powered by Nuclei web templates (XSS, SQLi, SSRF, IDOR, auth bypass, exposed panels), CVE enrichment, MITRE ATT&CK mapping, and a built-in crawler. Takes a domain, discovers endpoints, scans with web-focused Nuclei templates, enriches with NVD CVE data, outputs a pentest-ready report. CLI-native. No GUI, no Java, no enterprise price tag.

Release Candidate
WVS is in release candidate phase. Drop your email and we'll notify you the moment it's available.
๐Ÿ•ท๏ธ
Built-in Crawler
Takes a domain, recursively discovers endpoints, forms, APIs and JS references before scanning.
โšก
Nuclei Web Templates
XSS, SQLi, SSRF, IDOR, auth bypass, exposed admin panels โ€” web-focused template set curated for pentests.
๐Ÿ”
CVE Enrichment
Matches detected software versions against NVD CVE data โ€” surfaces exploitable web component vulnerabilities.
๐Ÿ—ก๏ธ
MITRE ATT&CK Mapping
Each finding mapped to ATT&CK tactics and techniques โ€” ready for red team reporting.
๐Ÿ”
Auth Bypass Testing
Tests login endpoints, JWT handling, session fixation, and insecure direct object references automatically.
๐Ÿ“„
Pentest-Ready Report
Structured HTML/JSON output with CVSS scores, evidence screenshots, and remediation guidance.