What it does
Nikto is a web server scanner, not an application scanner, and the distinction matters. It takes a host and port, fingerprints the server, then walks a large plaintext database of checks: paths that should not be reachable, default files left behind by installers, backup and source files with predictable names, administrative interfaces, directory indexing, and version banners that map to known-vulnerable software. Each check is a request and a match rule, and the tool simply issues them all and reports what came back.
There is no crawler in any meaningful sense and no attack logic beyond request and match. That simplicity is the design. Checks live in flat database files you can read and extend, output goes to text, CSV, XML, JSON or HTML, and the tool runs over SSL, through a proxy, against virtual hosts, with custom headers or with an authenticated session. It reads Nmap output to pick up discovered web ports. A set of evasion techniques is available for testing whether an intrusion detection system actually notices, though these are for controlled testing rather than stealth.
Where it fits
Nikto is a reconnaissance step, run early by a penetration tester or by an infrastructure team checking a server build. It answers "what obviously should not be here" in a minute or two, which is the right question before deeper manual work begins. It is also reasonable in a pipeline stage against a freshly deployed container to catch a debug endpoint or leftover installer file. You need network reachability and permission, nothing more.
Strengths
- Extremely fast to run and requires no configuration to produce useful output.
- The check database is a readable flat file, so adding organization-specific paths is trivial.
- Long-standing, stable output formats that other tools and scripts already parse.
- Finds the unglamorous exposures that application scanners skip entirely: leftover files, directory listings, default credentials pages.
Limitations
- It is extremely loud. No attempt is made to be quiet, so it fills logs and trips detection immediately.
- No JavaScript execution and no real crawling, so modern single-page applications are effectively invisible to it.
- Banner-based version checks produce false positives wherever software is backported or the banner is edited.
- It finds no injection, authorization or logic flaws. Treating a clean Nikto run as evidence of application security is a misreading of the tool.
Who it suits
A standard part of a penetration tester's early toolkit and a sensible sanity check for anyone deploying a web server. It is not a replacement for an application scanner and is poorly suited to teams expecting curated, low-noise findings routed to developers.
Used Nikto? Recommend it under your own name and title.
Recommend this tool