WhatWeb Docker
AI-generatedSummary
Runs the WhatWeb web fingerprinting tool (via Docker/Kali or direct Ubuntu) to detect web technologies, CMS, plugins, and headers.
Inputs
- targets (required) — One or more URLs to scan, separated by newlines. Must be targets the user owns or is authorized to test.
- scanCategory — Sets the scan profile (Stealth, Standard, Aggressive, Heavy, CMS Focused, Headers/Server Info, Plugin Preset, or Custom).
- aggression — Aggression level (1-4) for custom scan category.
- pluginPreset — Predefined plugin sets (CMS Common, All, WordPress, etc.) for specific scan categories.
- customPlugins — Custom list of plugins to scan.
- grep — Filters results using a text pattern or regex.
- followRedirect — How to handle redirects (Always, Same Site, HTTP Only, Meta Only, Never).
- maxRedirects — Maximum number of redirects to follow.
- headers — Custom HTTP headers to send with requests.
- userAgent — User-Agent string for requests.
- cookie — Cookie string for authentication.
- basicAuth — HTTP Basic Auth credentials in the format user:password.
- proxy — Proxy server address (e.g., 127.0.0.1:8080).
- proxyAuth — Proxy authentication credentials in the format user:password.
- urlPrefix — Prefix to add to targets.
- urlSuffix — Suffix to add to targets.
- urlPattern — URL pattern to apply to targets.
- threads — Number of concurrent threads (1-100).
- openTimeoutSeconds — Timeout for establishing a connection (1-300s).
- readTimeoutSeconds — Timeout for reading response data (1-300s).
- waitSeconds — Delay between requests in seconds (0-60s).
- executionMode — Execution mode: Docker CLI (default, runs in Kali container).
- directWhatwebCommand — Local WhatWeb command to use if execution mode is direct.
- dockerCommand — Docker command to use (default: docker).
- dockerContainer — Docker container to run WhatWeb in (default: kali-linux).
- timeoutSeconds — Timeout for the docker exec command itself (0-86400s).
Output shape
A single item containing a rich JSON object with scan results (technologies, CMS, plugins, headers, etc.) and diagnostic information.
The output includes a 'parsed' array with detailed technology findings, 'webSummary' with a structured report, 'warnings', 'errors', and raw stdout/stderr. Sensitive data (cookies, tokens, auth headers) is sanitized. A dedicated 'aiSummary' field provides a natural language overview.
Examples
Example 1: Scan a list of targets for WordPress detection using a stealth profile.
Targets: https://example.com, https://test.com; Scan Category: Stealth
Example 2: Perform a heavy scan of a specific URL to detect server stack and security headers.
Targets: https://example.com; Scan Category: Heavy
Example 3: Scan a target that requires authentication using HTTP Basic Auth.
Targets: https://example.com; Basic Auth: username:password