What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Maintenance status: development has been dormant for a long period, confirm before recommending
- License: the project has used a source-available license that is not straightforwardly OSI open source, verify terms
- Integration list left empty deliberately: confirm whether any are current
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Arachni is a scanner written in Ruby that crawls a web application and probes what it finds. Its distinguishing feature at the time it was actively developed was the integrated browser environment: rather than only parsing HTML for links, it spins up real browser instances to execute JavaScript, follow client side navigation and observe DOM mutations. That let it reach single page application routes and detect DOM based cross site scripting, which pure HTTP level scanners miss entirely.
Checks are organized as modules covering injection classes, cross site scripting including DOM variants, path traversal, file inclusion, cross site request forgery and a set of passive checks over responses. Around the checks sits a plugin system for tasks such as login sequence handling, proxying and result post processing, and an audit engine that tracks which inputs have been covered. It runs from the command line, from a Ruby API, or through a self hosted web interface that manages scan profiles and multiple scan workers.
Where it fits
Arachni is operated by a tester or a security engineer, usually from a terminal or a script, against a staging environment. Its command line orientation makes it straightforward to wrap in automation and to drive with different profiles per target. It was frequently used as the scanning engine behind in house security portals because of its API and distributed scan support. You need to supply scope rules and credentials yourself, and you need to be comfortable reading raw findings without a triage workflow layered on top.
Strengths
- Real browser execution for crawling and DOM based cross site scripting detection, uncommon among open source scanners of its generation.
- Fully scriptable through a command line interface and a Ruby API, which suits automation and custom harnesses.
- Distributed scanning across multiple workers for large targets.
- Fine grained control over which checks run and how inputs are audited.
Limitations
- Active development stopped years ago. New vulnerability classes, modern framework behavior and current JavaScript engines are not tracked, which is the decisive drawback for new adoption.
- The licensing has been a source of confusion: the project moved to terms that restrict commercial use, so treat the open source label with care.
- Browser driven crawling is resource hungry and slow on large applications.
- No modern ticketing, pipeline or reporting integrations to speak of.
Who it suits
Historically a strong choice for testers who wanted a scriptable open source scanner with genuine JavaScript handling, and it still has value for research, teaching and reproducing old results. For a team choosing a scanner today the dormancy makes it hard to justify over actively maintained alternatives. If you do use it, verify the license terms against your intended use first.
Used Arachni? Recommend it under your own name and title.
Recommend this tool