Web Recon
All-in-one web security scanner for pentesting, bug bounty, and security audits.
Scan any target with a single command and get a structured report with findings prioritized by severity. Modular — run the full suite or pick individual steps.
Why Use This
- One command → full security assessment with prioritized findings
- 12 scan modules — DNS, ports, fingerprinting, subdomains, directories, secrets, vulnerabilities, headers, CORS, SSL, WordPress, Nuclei templates
- Security header scoring — instant letter-grade for any site's HTTP security posture
- Secrets detection — 459 rules covering AWS, GCP, GitHub, Slack, databases, and more
- Skips missing tools gracefully — works with whatever you have installed
- Resume mode — pick up where a crashed scan left off
- JSON + Markdown reports — machine-readable and human-readable output
Quick Start
# Quick scan (recon, fingerprint, secrets, header scoring, report)
scripts/webscan.sh example.com --quick
# Full scan (all 12 steps)
scripts/webscan.sh example.com
# Full scan with JSON output and screenshot
scripts/webscan.sh example.com --json --screenshot
# Resume a crashed scan (skips completed steps)
scripts/webscan.sh example.com --resume
# Single step
scripts/webscan.sh example.com recon
scripts/webscan.sh example.com vulns
# Secrets scan only
scripts/titus-web.sh https://example.com
Output: ~/.openclaw/workspace/recon/<domain>/
Options
| Flag |
Description |
--quick |
Light scan: recon, fingerprint, secrets, vulns, report |
--full |
All steps (default) |
--json |
Generate results.json alongside markdown report |
--screenshot |
Capture homepage screenshot |
--resume |
Skip steps that already have output files |
Environment Variables
| Variable |
Purpose |
SHODAN_API_KEY |
Shodan API key for infrastructure intel (falls back to CLI) |
OUTDIR |
Override output directory |
Scan Modules
| Step |
What it does |
Tools |
recon |
DNS records, IP geolocation, port scan, Shodan, Wayback URLs |
nmap, dig, Shodan |
fingerprint |
HTTP headers, tech stack, WAF detection, CMS check |
WhatWeb, wafw00f |
subdomains |
Subdomain enumeration + live probing |
Subfinder, Amass, httpx |
dirs |
Directory and file bruteforce |
Gobuster, ffuf |
secrets |
Secrets scan + sensitive file checks (30+ paths) |
Titus (459 rules) |
vulns |
Security header scoring, CORS check, SSL analysis, vulnerability scan |
Nikto, custom |
wpscan |
WordPress-specific vulnerabilities (auto-skips if not WP) |
WPScan |
nuclei |
Template-based CVE scanning |
Nuclei |
ssl |
Full SSL/TLS analysis |
testssl |
screenshot |
Homepage capture |
cutycapt/chromium |
report |
Markdown + JSON report generation |
— |
Security Header Scoring
Scores 10 security headers by severity:
| Severity |
Points |
Headers |
| Critical |
30 |
Strict-Transport-Security, Content-Security-Policy |
| High |
20 |
X-Frame-Options |
| Medium |
10 |
X-Content-Type-Options, Referrer-Policy, Permissions-Policy |
| Low |
5 |
X-XSS-Protection, COOP, CORP, COEP |
Rating: 🟢 ≥80% · 🟡 ≥50% · 🟠 ≥25% · 🔴 <25%
Output Structure
~/.openclaw/workspace/recon/<domain>/
├── results.md # Markdown report with executive summary
├── results.json # Machine-readable report (--json)
├── screenshot.png # Homepage capture (--screenshot)
├── dns.txt / geo.json # DNS records, IP geolocation
├── ports.txt # nmap port scan results
├── shodan.json # Shodan infrastructure data
├── header-score.txt # Security header score card
├── cors.txt # CORS misconfiguration check
├── whatweb.txt / waf.txt # Tech fingerprint, WAF detection
├── subdomains-live.txt # Discovered live subdomains
├── dirs.txt # Discovered directories/files
├── sensitive-files.txt # Exposed config/backup files
├── titus.txt # Leaked secrets/API keys
├── nikto.txt / nuclei.txt # Vulnerability findings
├── ssl.txt # SSL/TLS analysis
└── wpscan.txt # WordPress scan (if applicable)
Review Priority
- header-score.txt — overall security posture at a glance
- sensitive-files.txt — any "FOUND" = critical exposure
- cors.txt — misconfigured CORS = data theft risk
- titus.txt — exposed secrets/API keys
- ports.txt — unexpected open ports
- nuclei.txt — known CVEs
- subdomains-live.txt — forgotten/dev subdomains
Tool Requirements
See references/tools.md for install instructions. Scripts skip missing tools gracefully — you don't need everything installed to get useful results.
Wordlists
See references/wordlists.md. Auto-selects medium wordlists, falls back to smaller if unavailable.
1---2name: web-recon3description: Website vulnerability scanner and security audit toolkit. Scan any website for security issues: open ports (nmap), exposed secrets, subdomain enumeration, directory bruteforce, security header scoring, CORS misconfigurations, SSL/TLS analysis, WordPress vulnerabilities, and more. One command, full report. Pentesting and OSINT reconnaissance for web applications.4---56# Web Recon78**All-in-one web security scanner for pentesting, bug bounty, and security audits.**910Scan any target with a single command and get a structured report with findings prioritized by severity. Modular — run the full suite or pick individual steps.1112## Why Use This1314- **One command** → full security assessment with prioritized findings15- **12 scan modules** — DNS, ports, fingerprinting, subdomains, directories, secrets, vulnerabilities, headers, CORS, SSL, WordPress, Nuclei templates16- **Security header scoring** — instant letter-grade for any site's HTTP security posture17- **Secrets detection** — 459 rules covering AWS, GCP, GitHub, Slack, databases, and more18- **Skips missing tools gracefully** — works with whatever you have installed19- **Resume mode** — pick up where a crashed scan left off20- **JSON + Markdown reports** — machine-readable and human-readable output2122## Quick Start2324```bash25# Quick scan (recon, fingerprint, secrets, header scoring, report)26scripts/webscan.sh example.com --quick2728# Full scan (all 12 steps)29scripts/webscan.sh example.com3031# Full scan with JSON output and screenshot32scripts/webscan.sh example.com --json --screenshot3334# Resume a crashed scan (skips completed steps)35scripts/webscan.sh example.com --resume3637# Single step38scripts/webscan.sh example.com recon39scripts/webscan.sh example.com vulns4041# Secrets scan only42scripts/titus-web.sh https://example.com43```4445Output: `~/.openclaw/workspace/recon/<domain>/`4647## Options4849| Flag | Description |50|------|------------|51| `--quick` | Light scan: recon, fingerprint, secrets, vulns, report |52| `--full` | All steps (default) |53| `--json` | Generate `results.json` alongside markdown report |54| `--screenshot` | Capture homepage screenshot |55| `--resume` | Skip steps that already have output files |5657## Environment Variables5859| Variable | Purpose |60|----------|---------|61| `SHODAN_API_KEY` | Shodan API key for infrastructure intel (falls back to CLI) |62| `OUTDIR` | Override output directory |6364## Scan Modules6566| Step | What it does | Tools |67|------|-------------|-------|68| `recon` | DNS records, IP geolocation, port scan, Shodan, Wayback URLs | nmap, dig, Shodan |69| `fingerprint` | HTTP headers, tech stack, WAF detection, CMS check | WhatWeb, wafw00f |70| `subdomains` | Subdomain enumeration + live probing | Subfinder, Amass, httpx |71| `dirs` | Directory and file bruteforce | Gobuster, ffuf |72| `secrets` | Secrets scan + sensitive file checks (30+ paths) | Titus (459 rules) |73| `vulns` | Security header scoring, CORS check, SSL analysis, vulnerability scan | Nikto, custom |74| `wpscan` | WordPress-specific vulnerabilities (auto-skips if not WP) | WPScan |75| `nuclei` | Template-based CVE scanning | Nuclei |76| `ssl` | Full SSL/TLS analysis | testssl |77| `screenshot` | Homepage capture | cutycapt/chromium |78| `report` | Markdown + JSON report generation | — |7980## Security Header Scoring8182Scores 10 security headers by severity:8384| Severity | Points | Headers |85|----------|--------|---------|86| Critical | 30 | Strict-Transport-Security, Content-Security-Policy |87| High | 20 | X-Frame-Options |88| Medium | 10 | X-Content-Type-Options, Referrer-Policy, Permissions-Policy |89| Low | 5 | X-XSS-Protection, COOP, CORP, COEP |9091Rating: 🟢 ≥80% · 🟡 ≥50% · 🟠 ≥25% · 🔴 <25%9293## Output Structure9495```96~/.openclaw/workspace/recon/<domain>/97├── results.md # Markdown report with executive summary98├── results.json # Machine-readable report (--json)99├── screenshot.png # Homepage capture (--screenshot)100├── dns.txt / geo.json # DNS records, IP geolocation101├── ports.txt # nmap port scan results102├── shodan.json # Shodan infrastructure data103├── header-score.txt # Security header score card104├── cors.txt # CORS misconfiguration check105├── whatweb.txt / waf.txt # Tech fingerprint, WAF detection106├── subdomains-live.txt # Discovered live subdomains107├── dirs.txt # Discovered directories/files108├── sensitive-files.txt # Exposed config/backup files109├── titus.txt # Leaked secrets/API keys110├── nikto.txt / nuclei.txt # Vulnerability findings111├── ssl.txt # SSL/TLS analysis112└── wpscan.txt # WordPress scan (if applicable)113```114115## Review Priority1161171. **header-score.txt** — overall security posture at a glance1182. **sensitive-files.txt** — any "FOUND" = critical exposure1193. **cors.txt** — misconfigured CORS = data theft risk1204. **titus.txt** — exposed secrets/API keys1215. **ports.txt** — unexpected open ports1226. **nuclei.txt** — known CVEs1237. **subdomains-live.txt** — forgotten/dev subdomains124125## Tool Requirements126127See [references/tools.md](references/tools.md) for install instructions. Scripts skip missing tools gracefully — you don't need everything installed to get useful results.128129## Wordlists130131See [references/wordlists.md](references/wordlists.md). Auto-selects medium wordlists, falls back to smaller if unavailable.