Features

 

Get Started Quickly

Websecurify is a hustle-free web application security testing tool. All you need to do to start a test is to enter the url of the application. You don't need to configure anything special, deal with complex setups, resolve dependencies or just do anything else, which stands between you and your goal.

Websecurify was designed to be elegant, quick, efficient but most of all smart. Our testing engine will choose the best possible strategy for the target application by default.

Adjustable Test Scope and Authentication

In case you need to do authenticated testing or you just want to make sure that certain parts of your application must not be tested, we have integrated a powerful built-in browser and test scoping tool with a unique set of features.

Start the built-in browser to authenticate and perform other application initialisation functions just as you do with your normal browser. If you find resources which you do not want to be included into the test simply select the scope tab and exclude them with a single click.

Simultaneous Testing

Most web application security testing tools out there allow you to do only one test at a time. This is such a waste of time and resources and certainly not something we can allow to slip through.

Websecurify is fully capable to manage multiple concurrent tests inside a single testing window, by which all of the results will be merged into a single report, or multiple testing windows, which will have separate settings, results and of course unique reports.

Advanced Reporting

Websecurify has a powerful reporting engine capable of producing reports in great detail. All issues are clearly explained and examples provides. Websecurify will also take screenshots for some vulnerabilities as a proof that the problem was accurately identified.

All issues are exportable in numerous file formats. You can even export your reports into JSON and XML formats, which provide even more details about how issues were identified.

Just the Start...

Here is a summary of some of the features we think you might want to know about.

  • Fast, elegant and easy to use
  • Platform independent
  • Full-support for mobile devices
  • Reports in XML, JSON, CSV, HTML and RTF
  • Translated in several languages (Feb 2012)
  • Flexible Licensing (DRM FREE)
  • Automatic screenshots of vulnerabilities
  • Easy to use extension technology
  • Built-in browser and test scoping tool
  • Hustle-free updates
  • Future-proof (soon available in a server)
  • Support for OWASP Top 10, etc.

Leading by Example...

Websecurify is driving innovation to new frontiers. We push the boundaries and constantly challenge the status quo.

Flexible Licensing

Are you tired of complex licensing schemes with multiple levels of feature locking. Perhaps the solution you bought is locked to just 3 nominated web applications? We think that this is simply unacceptable.

We have pioneered a new way to get our product to you without the complex licensing schemes you get from other vendors. When you buy a major version of Websecurify you can use it as much as you want for as long as you need and you get all software updates for it. For example, if you buy Websecurify 1.0.2 today you get all software updates for this major version. In other words you get everything up to version 2.0. When Websecurify 2.0 come out you will have the chance to evaluate it and decide if you want to buy it and you can still use the older version without any restrictions. It is as simple as that.

Simplicity Throughout

Websecurify is proven to be the most easy to use web application security testing tool out there. Websecurify uses innovative, clutter-free, easy and quick to get around user interface. Designed with simplicity in mind, Websecurify provides easy but very rich and powerful testing workflow suitable for experts and casual users alike.

Resource Efficiency

Websecurify has pioneered the concept of fully stateless, asynchronous (non-block) web application security testing engine. This makes Websecurify very resilient to heavy load. All internal Websecurify functions are designed for memory and process efficiency.

Vulnerably Screenshots

Websecurify is the first and only web application security tool, which has capabilities to take full page screenshots for many classes of vulnerabilities such as SQL Injection, Local and Remote File Include, various types of information disclosure bugs and many more.

Mobile Devices

Websecurify Mobile is the fist and only web application security testing tool for Apple iOS (iPhone, iPad and iPod), Android and others. Websecurify Mobile provides all benefits and features of the desktop and server versions available at anytime from anywhere from the convenience and comfort of your mobile device.

» See Websecurify for Apple iOS.

Browser Environments

Websecurify is the first and only fully functional web application security testing tool, which can execute from any web page inside your browser (subject to same origin policies). Websecurify is also the first fully functional web application security testing tool available as a browser extension for Mozilla Firefox and Google Chrome.

Feature Comparison...

The following table illustrates some of the main differences between all Websecurify editions. Do not hesitate to contact us if you need more information.

Feature/EditionWebsecurify Browser ExtensionsWebsecurify BasicWebsecurify MobileWebsecurify Advanced
Unlimited targets
Automatic updates 
Faster release cycles  
Export to XML, JSON, HTML, RTF, CVS, etc.   
Email Reports   
Automatic vulnerability screenshots   
Report filters  
Simultaneous testing of multiple targets   
Simultaneous execution of multiple testing windows   
Built-in browser and Test Scope Adjusting tool   
3rd-party extensions  
Basic testing engine  
Mobile testing engine   
Advanced testing engine   
Mobile-centric User Interface   
Desktop-centric User Interface 

Legend:

iOS Mac Window Ubuntu Chrome Firefox