| Plugin | ms | Reqs | Quality |
| Path Traversal | 0:03:17.845 | 19998 | release |
| Remote File Inclusion | 0:03:19.899 | 12591 | release |
| Server Side Include | 0:03:17.682 | 10172 | release |
| Cross Site Scripting (Reflected) | 0:03:17.577 | 7500 | release |
| Cross Site Scripting (Persistent) - Prime | 0:03:13.952 | 2578 | release |
| Cross Site Scripting (Persistent) - Spider | 0:03:12.294 | 1966 | release |
| Cross Site Scripting (Persistent) | 0:01:56.056 | 0 | release |
| SQL Injection | 0:03:21.200 | 18019 | release |
| Server Side Code Injection | 0:03:17.921 | 20623 | release |
| Remote OS Command Injection | 0:03:18.371 | 30935 | release |
| Directory Browsing | 0:03:12.278 | 1966 | release |
| External Redirect | 0:03:17.850 | 7640 | release |
| Buffer Overflow | 0:03:14.035 | 2434 | release |
| Format String Error | 0:03:16.276 | 7259 | release |
| CRLF Injection | 0:03:17.602 | 18046 | release |
| Parameter Tampering | 0:03:16.932 | 16189 | release |
| Script Active Scan Rules | 0:00:00.001 | 0 | release |
| Source Code Disclosure - SVN | 0:03:01.447 | 1867 | beta |
| Source Code Disclosure - /WEB-INF folder | 0:00:00.012 | 4 | beta |
| Remote Code Execution - Shell Shock | 0:03:17.353 | 5156 | beta |
| Anti CSRF Tokens Scanner | 0:01:08.645 | 606 | beta |
| Heartbleed OpenSSL Vulnerability | 0:00:00.004 | 3 | beta |
| Cross-Domain Misconfiguration | 0:00:00.030 | 2 | beta |
| Source Code Disclosure - CVE-2012-1823 | 0:02:42.605 | 1613 | beta |
| Remote Code Execution - CVE-2012-1823 | 0:03:16.899 | 3932 | beta |
| Session Fixation | 0:00:01.774 | 0 | beta |
| SQL Injection - MySQL | 0:22:51.371 | 10028 | beta |
| SQL Injection - Hypersonic SQL | 0:03:18.802 | 10309 | beta |
| SQL Injection - Oracle | 0:03:17.719 | 10312 | beta |
| SQL Injection - PostgreSQL | 0:03:17.703 | 10309 | beta |
| Advanced SQL Injection | 0:23:50.752 | 591629 | beta |
| XPath Injection | 0:03:20.016 | 7734 | beta |
| XML External Entity Attack | 0:00:01.045 | 0 | beta |
| Generic Padding Oracle | 0:01:56.450 | 2 | beta |
| Expression Language Injection | 0:03:14.703 | 2543 | beta |
| Backup File Disclosure | 0:03:09.572 | 33296 | beta |
| Integer Overflow Error | 0:03:15.334 | 9558 | beta |
| Insecure HTTP Method | 0:03:11.684 | 1966 | beta |
| HTTP Parameter Pollution scanner | 0:01:10.523 | 558 | beta |
| Possible Username Enumeration | 0:00:00.000 | 0 | beta |
| Source Code Disclosure - Git | 0:00:14.742 | 0 | alpha |
| Source Code Disclosure - File Inclusion | 0:28:06.332 | 7793 | alpha |
| Httpoxy - Proxy Header Misuse | 0:03:17.682 | 7864 | alpha |
| LDAP Injection | 2:17:03.531 | 16486 | alpha |
| SQL Injection - SQLite | 0:03:20.809 | 51186 | alpha |
| Cross Site Scripting (DOM Based) | 0:03:42.909 | 456 | alpha |
| SQL Injection - MsSQL | 0:03:18.975 | 6510 | alpha |
| Example Active Scanner: Denial of Service | 0:01:53.625 | 0 | alpha |
| An example active scan rule which loads data from a file | 0:01:56.644 | 0 | alpha |
| SOAP Action Spoofing | 0:00:04.185 | 0 | alpha |
| SOAP XML Injection | 0:01:57.000 | 0 | alpha |
| Relative Path Confusion | 0:03:06.704 | 1892 | alpha |
| Apache Range Header DoS (CVE-2011-3192) | 0:03:12.754 | 1974 | alpha |
| User Agent Fuzzer | 0:03:17.471 | 13727 | alpha |
| HTTP Only Site | 0:00:00.012 | 0 | alpha |
| Proxy Disclosure | 0:03:17.879 | 11796 | alpha |
| ELMAH Information Leak | 0:00:00.020 | 1 | alpha |
| Trace.axd Information Leak | 0:00:11.585 | 70 | alpha |
| HTTPS Content Available via HTTP | 0:00:02.180 | 0 | alpha |
| Cookie Slack Detector | 0:03:17.878 | 13302 | alpha |
| | | |
| Total | 5:41:55 | - | - |