Comparison of the effectiveness of tools for testing the security of web applications

Main Article Content

DOI

Izabela Kaźmierak

izabela.kazmierak@pollub.edu.pl

Abstract


This article presents a comparative analysis of the effectiveness of three web application security scanners: ZAP, Wapiti, and Skipfish. Automated scanning was conducted on deliberately unsecured applications, followed by an analysis of the detected vulnerabilities. The results were presented in the form of comparative tables and graphs illustrating the number and types of detected threats. The analysis showed that ZAP detected the most vulnerabilities, particularly in low-risk categories, Skipfish excelled in identifying specific threats, while Wapiti was effective in finding simple vulnerabilities. The study demonstrated the need to combine different scanners and supplement them with manual tests for a comprehensive assessment of web application security.


Keywords:

web application security, testing tools, cybersecurity

References

Article Details

Kaźmierak, I. (2025). Comparison of the effectiveness of tools for testing the security of web applications. Journal of Computer Sciences Institute, 34, 36–43. https://doi.org/10.35784/jcsi.6613