Alternatives to Pentest-Tools.com
An online toolkit of vulnerability scanners and penetration testing tools that produces customizable reports. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Pentest-Tools.com
An online toolkit of vulnerability scanners and penetration testing tools that produces customizable reports.
Replacements
Listings that take over the same core job as Pentest-Tools.com.
Qualys Community Edition
Free, cloud-based edition of the Qualys security platform for asset discovery and vulnerability assessment.
Qualys Community Edition offers free cloud vulnerability assessment and asset discovery with compliance checks, limited to a small number of IPs.
HackerTarget WhatWeb Scan
An online scan that runs WhatWeb and Wappalyzer to fingerprint the technologies behind a website.
HackerTarget WhatWeb Scan belongs to a freemium set of online scanning tools, focused on fingerprinting rather than exploit-validated vulnerability reports.
Also worth comparing
These listings name Pentest-Tools.com as their own alternative, so the relationship runs both ways.
Metasploit Framework
The standard open-source exploitation framework for authorised penetration testing and verifying that a vulnerability is real.
Pentest-Tools.com is a hosted commercial toolkit that validates vulnerabilities with exploits and produces reports, running on the vendor's infrastructure.
Nessus
Widely used commercial vulnerability scanner.
Pentest-Tools.com is a hosted toolkit of scanners that validates findings with exploits and produces audit-ready reports.
Nuclei
A fast vulnerability scanner driven by YAML templates contributed by thousands of security researchers.
Pentest-Tools.com runs scanners in the browser on the vendor's infrastructure, validates findings with exploits and produces reports, with the full feature set on paid plans.
OpenVAS
Full-featured open-source vulnerability scanner.
Pentest-Tools.com runs scans from the browser on vendor infrastructure, validates findings with exploits and generates reports, with the full feature set behind paid plans.
Wapiti
Check web applications with a Python-based vulnerability scanner.
Pentest-Tools.com runs scans in the browser on the vendor's infrastructure and produces customizable reports, with the full feature set behind paid plans instead of free open source.
WPSec
An online scanner that checks WordPress sites for known vulnerabilities in core, plugins and themes.
Pentest-Tools.com offers general vulnerability scanners that validate findings with exploits and produce audit reports, with the full feature set behind paid plans.
ZAP
Open-source web application security scanner and intercepting proxy.
Pentest-Tools.com runs vulnerability scans in the browser on vendor infrastructure with customizable reports, moving from free open source to a commercial service with paid plans.
Similar software
Related functionality, not a direct replacement.
Sucuri SiteCheck
Free remote scanner that checks a website for visible malware, blocklisting and outdated software.
wafw00f
Command-line tool that identifies and fingerprints web application firewalls in front of a site.
WhatWeb
Command-line web scanner that fingerprints the technologies running on a website.
testssl.sh
A free command-line tool that checks a server's TLS/SSL ciphers, protocols and cryptographic flaws.
HTTP Observatory
Mozilla's web tool that grades a site's HTTP security headers and gives fix recommendations.