Skip to content

Nikto

Scan web servers for outdated software, dangerous files, and misconfigurations.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 8700

Open the official app on cirt.net

This tool is hosted by its maintainers. Click below to open cirt.net in a new tab — it's their official demo.

Browse security tools →

What's next with Nikto?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Nikto?

Nikto is an open-source web server scanner designed to identify vulnerabilities, misconfigurations, and outdated software on web servers. It is primarily used by security professionals, penetration testers, and system administrators to assess the security posture of web applications and infrastructure. The tool scans for over 8,000 potentially dangerous files and programs, checks for outdated server components, and detects common misconfigurations such as exposed default files or insecure HTTP settings. Nikto addresses the problem of identifying exploitable weaknesses in web servers that could lead to data breaches, unauthorized access, or information leaks. By automating the discovery of these issues, it streamlines the security assessment process and provides actionable insights for remediation.

How it works

Nikto is a command-line tool that performs comprehensive scans of web servers to uncover security risks. It is part of the cybersecurity toolkit for professionals tasked with hardening systems and conducting penetration tests. Its primary purpose is to detect vulnerabilities such as exposed sensitive files, outdated software versions, and misconfigured server settings. The tool is particularly valuable for identifying issues that may not be apparent through manual inspection. By leveraging a database of known vulnerabilities and misconfigurations, Nikto helps users prioritize remediation efforts and strengthen their web infrastructure. Nikto scans for dangerous files like.htaccess, backup scripts, and default server pages, which could expose sensitive data. It also identifies outdated versions of web servers (e.g., Apache, IIS) and components, which are often targets for exploits. The tool checks for misconfigurations such as multiple index files, directory listings, and HTTP server options that could leak information or allow unauthorized access. It supports IPv4 and IPv6, HTTP protocols, and generates reports in formats like HTML for easy analysis.

How to use it

  1. 1Install Nikto via GitHub or package managers like apt. 2. Run the tool with the -host parameter to specify the target IP or domain. 3. Use options like -Display, -Tuning, and -Format to customize the scan and output. 4. Review the generated report to identify vulnerabilities and misconfigurations. Practical tips include updating plugins regularly, using the -o flag to save results, and combining Nikto with other tools for deeper analysis.

What it can do

  • web server vulnerability scanner

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/sullo/nikto
  • license: GPL-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Focuses on coverage and accuracy over speed, which may result in slower scans
  • May produce false positives that require manual verification
  • Relies on a database of known vulnerabilities that may not include newer exploits
  • Requires manual interpretation of results, which can be time-consuming

Understanding the result

Scan web servers for outdated software, dangerous files, and misconfigurations.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(sullo/nikto)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with sullo/nikto. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Nikto used for?

Nikto is used to scan web servers for vulnerabilities, misconfigurations, and outdated software. It helps security professionals identify risks such as exposed files, insecure HTTP settings, and vulnerable server components. The tool is essential for penetration testing, system hardening, and compliance checks.

How does Nikto detect vulnerabilities?

Nikto sends HTTP requests to a target server and analyzes responses for signs of vulnerabilities. It checks for exposed files, outdated software versions, and misconfigurations by comparing server responses to a database of known issues. Plugins and tuning options allow customization of the scan to target specific risks.

How do I run a basic Nikto scan?

Install Nikto via GitHub or package managers. Run the command 'nikto -host example.com -Format html -o report.html' to scan the target domain. The -host parameter specifies the target, -Format defines the output type, and -o saves the results. Adjust tuning options like -Display or -Tuning for specific checks.

How does Nikto compare to alternatives like Nmap or OpenVAS?

Nikto specializes in web server scanning and focuses on identifying misconfigurations and exposed files, while Nmap is broader, targeting network services and ports. OpenVAS offers more comprehensive vulnerability assessment with detailed risk analysis. Nikto is ideal for quick web server checks, whereas OpenVAS provides deeper, automated security assessments.

How do I troubleshoot a 'Connection refused' error in Nikto?

A 'Connection refused' error typically indicates the target server is unreachable. Verify the IP address or domain name, ensure the server is online, and check firewall rules blocking the connection. If the server uses HTTPS, use the -ssl flag. Ensure the target port (e.g., 80 for HTTP) is open and accessible.

Spotted something wrong with Nikto, or want to maintain it? See how to help.