The Unvalidated Redirect Detection Accuracy of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016, Currently compares 15 scanners
Sorted in a descending order according to the scanner unvalidated redirect detection ratio and product name.
Hint: click the version link to get more information about each scanner evaluation, and the product name to get detailed information on the product.

Unified List   Commercial Scanners   Free / Open Source Scanners


Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
arachni1.1Tasos Laskos100.00% Detection Rate
0.00% False Positives
(30/60)
(0/9)
2
IronWASP0.9.7.4Lavakumar Kuppan73.33% Detection Rate
11.11% False Positives
(22/60)
(1/9)
3
W3AF1.6W3AF developers63.33% Detection Rate
11.11% False Positives
(19/60)
(1/9)
4
SkipFish2.10Michal Zalewski - Google36.67% Detection Rate
0.00% False Positives
(11/60)
(0/9)
5
ZAP2.2.2OWASP16.67% Detection Rate
0.00% False Positives
(5/60)
(0/9)
6
Andiparos1.0.6Compass Security AG6.67% Detection Rate
0.00% False Positives
(2/60)
(0/9)

Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.