Skip to content

Nikto PlatformWeb Security Testing

Web-server scanning, crawling, content discovery, and LFI file retrieval — one browser console.

Tools in one console ​

The Nikto Platform puts complementary scanners behind a single UI. Launch them from the New Scan wizard or a host's tool tab.

Nikto Scanner ​

Nikto is a classic web server scanner. Point it at HTTP or HTTPS targets and it runs a large library of checks: default files, misconfigurations, headers, SSL issues, outdated components, and other common web weaknesses. Nikto scans can run over HTTP/3 (QUIC) when you opt in — see HTTP/3 scanning. LFIC and Bustah can use the same transport via Scan Defaults; the crawler cannot. Results appear as findings you can triage, add to a report, and export.

See Scans for the wizard and progress monitoring, and Scan options for Nikto modules and MS10-070. The Web Crawler and Bustah can run in the same launch.

LFI Commander ​

LFI Commander (shown in the UI as LFIC) is for local file inclusion vulnerabilities. You describe how the target includes files (the inject point, encoding, wrappers), confirm the flaw with a probe, then run scans built from modules and filesets to retrieve interesting paths. Retrieved files appear in a browsable tree with extracted content, intel from analysis modules, and zip downloads.

See LFIC for the setup wizard, modules, and results explorer.

Projects, findings, and audit ​

Projects and hosts organize targets. Findings and Report are where you triage and curate results. The activity log records every HTTP request to a target. A valid license is required to start new work against a target. Start with Getting Started or the User Guide.


Copyright © 2026 Hack LLC. All rights reserved. View the End User License Agreement.

Proprietary software. Licensed for use under the End User License Agreement.