Website vulnerability scanning extension

Dhruv N. Desai, Harsh Baria, Arun Chauhan, Gourav Yadav, Mukesh Patidar, Mihir Mahale, Abhijit Dave, Shubh Patel · IET conference proceedings. · 2025

Such vulnerability scanning continues even as attacks of this kind rise in complexity by targeting the whole website, a reason for secure web applications and thus more concern about it, as many software tools of these traditional tools based on the classic vulnerability scanner would be applied against websites but it is found the browser-based site vulnerability scanner was convenient. This paper attempts to investigate the functionality and effectiveness of website vulnerability scanning extensions such as Wappalyzer, No Script, Burp Suite, and Security Headers. The study analyses how these extensions enhance security testing by giving real-time information on vulnerabilities like XSS, SQL Injection, and insecure HTTP headers. The results are crucial to understanding the significance of incorporating these tools into the web development workflow, as well as their limitations. It concludes by recommending using vulnerability scanning extensions along with comprehensive security testing for a more robust web application security posture.

Read the paper · More papers on PaperTik