
Nikto
Nikto is a free open-source web server scanner that checks authorised targets for dangerous files, misconfigurations and outdated software.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 2 October 2026
What it is
Nikto is a free open-source web server scanner by Chris Sullo (github.com/sullo/nikto, associated with cirt.net). In authorised assessments and Hack The Box Academy web modules, it probes HTTP services for dangerous files, outdated server software and common misconfigurations as a fast first-pass check beside directory tools and proxies.
What it helps with
- Scanning authorised web servers for known risky paths and configuration issues.
- Flagging outdated server banners and common CGI or script exposures for manual follow-up.
- Supporting HTB Academy and early web-assessment labs where broad, noisy checks are expected.
- Producing CSV, XML or text reports for evidence packs in scoped tests.
- Running as a Perl-based CLI under GPL-3.0 for the core code without a commercial fee.
- Complementing content discovery (for example Gobuster or Feroxbuster) and authenticated proxy testing.
Who it's for
Web penetration testers and HTB Academy learners who need a classic free web server scanner for authorised targets as a peer to Nuclei and commercial DAST tools.
Worth knowing
Nikto core code is GPL-3.0; its database files have separate distribution terms for use with Nikto (see cirt.net / project licensing wiki). Official GitHub: github.com/sullo/nikto. Authorised testing only; scans are noisy and must stay in scope.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.