The Path Traversal / Local File Inclusion Detection Accuracy of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016, Currently compares 23 scanners
Sorted in a descending order according to the scanner Path Traversal/LFI detection ratio and product name.
Hint: click the version link to get more information about each scanner evaluation, and the product name to get detailed information on the product.

Unified List   Commercial Scanners   Free / Open Source Scanners


Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
arachni1.1Tasos Laskos100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
1
IBM AppScan9.0.0.999 / 8.8.0.0IBM Security Systems Division100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
1
Netsparker4.1.1.0Netsparker Ltd100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
1
Tinfoil SecurityXTinfoil Security100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
2
Netsparker Cloud2015-06-16Netsparker Ltd94.36% Detection Rate
0.00% False Positives
(770/816)
(0/8)
3
Acunetix WVS10.5Acunetix94.12% Detection Rate
0.00% False Positives
(768/816)
(0/8)
4
Vega1.0Subgraph94.12% Detection Rate
62.50% False Positives
(768/816)
(5/8)
5
N-StalkerXN-Stalker92.77% Detection Rate
12.50% False Positives
(757/816)
(1/8)
6
WebInspect10.1.177.0HP Application Security Center91.18% Detection Rate
0.00% False Positives
(744/816)
(0/8)
7
SkipFish2.10Michal Zalewski - Google82.35% Detection Rate
25.00% False Positives
(672/816)
(2/8)
8
AppSpider6.0Rapid781.13% Detection Rate
12.50% False Positives
(662/816)
(1/8)
9
ZAP2.2.2OWASP75.00% Detection Rate
0.00% False Positives
(612/816)
(0/8)
10
Burp Suite Professional1.7.03PortSwigger69.12% Detection Rate
12.50% False Positives
(564/816)
(1/8)
11
Ammonite1.2RyscCorp.63.97% Detection Rate
37.50% False Positives
(522/816)
(3/8)
12
W3AF1.6W3AF developers57.48% Detection Rate
12.50% False Positives
(469/816)
(1/8)
13
IronWASP0.9.7.4Lavakumar Kuppan53.06% Detection Rate
0.00% False Positives
(433/816)
(0/8)
14
Syhunt Dynamic5.0.0.7Syhunt52.94% Detection Rate
0.00% False Positives
(432/816)
(0/8)
15
Wapiti2.3.0OWASP51.47% Detection Rate
12.50% False Positives
(420/816)
(1/8)
16
JSky (Commercial Edition)3.5.1NoSec48.53% Detection Rate
12.50% False Positives
(396/816)
(1/8)
17
WATOBO0.9.19Andreas Schmidt41.18% Detection Rate
0.00% False Positives
(336/816)
(0/8)
18
WebSecurify (Opensource Version)0.9GNU Citizen31.62% Detection Rate
0.00% False Positives
(258/816)
(0/8)
19
ParosPro1.9.12MileSCAN Technologies12.75% Detection Rate
37.50% False Positives
(104/816)
(3/8)
20
safe3wvs (limited free edition)10.1Safe3 Network Center8.58% Detection Rate
12.50% False Positives
(70/816)
(1/8)

Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.