The Remote File Inclusion Detection Accuracy of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016, Currently compares 19 scanners
Sorted in a descending order according to the scanner Remote File Inclusion (RXSS via RFI) detection ratio and product name.
Hint: click the version link to get more information about each scanner evaluation, and the product name to get detailed information on the product.

Unified List   Commercial Scanners   Free / Open Source Scanners


Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
Acunetix WVS10.5Acunetix100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
arachni1.1Tasos Laskos100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
IBM AppScan9.0.0.999 / 8.8.0.0IBM Security Systems Division100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
Netsparker4.1.1.0Netsparker Ltd100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
Netsparker Cloud2015-06-16Netsparker Ltd100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
Tinfoil SecurityXTinfoil Security100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
Vega1.0Subgraph100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
1
WebInspect10.1.177.0HP Application Security Center100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
2
ZAP2.2.2OWASP100.00% Detection Rate
16.67% False Positives
(108/108)
(1/6)
3
N-StalkerXN-Stalker92.59% Detection Rate
0.00% False Positives
(100/108)
(0/6)
4
Burp Suite Professional1.7.03PortSwigger85.19% Detection Rate
0.00% False Positives
(92/108)
(0/6)
5
AppSpider6.0Rapid779.63% Detection Rate
0.00% False Positives
(86/108)
(0/6)
6
IronWASP0.9.7.4Lavakumar Kuppan77.78% Detection Rate
0.00% False Positives
(84/108)
(0/6)
7
Wapiti2.3.0OWASP57.41% Detection Rate
0.00% False Positives
(62/108)
(0/6)
8
Syhunt Dynamic5.0.0.7Syhunt44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
8
Syhunt Mini (Sandcat Mini)4.4.3.0Syhunt44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
9
Ammonite1.2RyscCorp.44.44% Detection Rate
33.33% False Positives
(48/108)
(2/6)
10
SkipFish2.10Michal Zalewski - Google31.48% Detection Rate
16.67% False Positives
(34/108)
(1/6)
11
JSky (Commercial Edition)3.5.1NoSec22.22% Detection Rate
0.00% False Positives
(24/108)
(0/6)
12
W3AF1.6W3AF developers16.67% Detection Rate
16.67% False Positives
(18/108)
(1/6)

Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.