WappaCVElyze 作者: cw
See the technologies behind any site with their versions, colour-coded by known vulnerabilities: current, outdated, end-of-life, vulnerable (CVE) or actively exploited (CISA KEV).
可在 Android™ 版 Firefox 上使用可在 Android™ 版 Firefox 上使用
扫码在 Android 版 Firefox 中打开此扩展
扩展元数据
屏幕截图
关于此扩展
WappaCVElyze identifies the web technologies behind the page you are on — server software, CMS, frameworks, JavaScript libraries — and, unlike a plain technology detector, shows the detected version and whether that version is safe.
Each technology gets a verdict:
• Current — newest release of a maintained cycle, no known CVE
• Outdated — no known CVE, but a newer release exists
• End of life — the release cycle no longer receives fixes
• Vulnerable — a CVE applies to this exact version, with the affected range, CVSS, EPSS exploitation probability and public-exploit flags
• Critical — the CVE is on CISA's Known Exploited Vulnerabilities catalog
Every red row links to the NVD record, the CISA entry and the vendor advisory that confirm it.
Verdicts come from a small database built daily from public sources (NVD, CISA KEV, FIRST EPSS, endoflife.date, Retire.js, Nuclei and Metasploit exploit indexes) and downloaded once a day. Page content is analysed locally and never leaves your browser; the site you visit is never sent anywhere. Privacy policy for every request the extension makes: https://github.com/xZoroo/wappacvelyze/blob/main/PRIVACY.md.
Open source (MIT): https://github.com/xZoroo/wappacvelyze — a command-line scanner with the same verdicts is included.
Each technology gets a verdict:
• Current — newest release of a maintained cycle, no known CVE
• Outdated — no known CVE, but a newer release exists
• End of life — the release cycle no longer receives fixes
• Vulnerable — a CVE applies to this exact version, with the affected range, CVSS, EPSS exploitation probability and public-exploit flags
• Critical — the CVE is on CISA's Known Exploited Vulnerabilities catalog
Every red row links to the NVD record, the CISA entry and the vendor advisory that confirm it.
Verdicts come from a small database built daily from public sources (NVD, CISA KEV, FIRST EPSS, endoflife.date, Retire.js, Nuclei and Metasploit exploit indexes) and downloaded once a day. Page content is analysed locally and never leaves your browser; the site you visit is never sent anywhere. Privacy policy for every request the extension makes: https://github.com/xZoroo/wappacvelyze/blob/main/PRIVACY.md.
Open source (MIT): https://github.com/xZoroo/wappacvelyze — a command-line scanner with the same verdicts is included.
评分 0(1 位用户)
权限与数据
更多信息