Skip to content

Getting Started ​

Open the Nikto Platform console and run your first scan.

Open the console ​

Open the web console in your browser. The address is the one your installer gave you (often http://localhost:3001). The console opens only on the machine that runs it; to use it from another computer, see Remote Access.

On first open, the console shows Create the admin account instead of your projects. Get a setup code from the host (nikto-launcher admin setup-code) and use it to create your username and password — see Operator Login. After that, each visit shows a sign-in screen until you sign in. The Projects screen is the home of the console once you are signed in.

Not installed yet? Check the system requirements, then install with the launcher. Docker Deployment covers installing, Chromium for Headless Browser crawls, and uninstalling.

License required for new work

Nikto Platform requires a valid license before you can start new work against a target. On first use you may also need to accept the End User License Agreement. Install a license under Global Settings → License — see the License guide. When the license is missing, expired, or invalid, a red banner appears. Start Scan, the LFIC setup probe, reopening a finished Bustah sweep, and Export full file list are refused. Scans that are already running or paused finish.

The layout ​

  • Top bar — the Nikto logo and the arrow beside it (both return to Projects) and the light/dark theme toggle.
  • Left sidebar — navigation. When a project is open, it shows Hosts, an expandable Tools group (Nikto, Crawl, LFIC, Bustah), then Scans, Recommendations, Findings, Report, Logs, and Settings. Recommendations, Findings, and Report show open-item counters. The lower part of the sidebar always shows global items: Active Jobs, Status (opens /nikto-diag diagnostics in a new tab), and Global Settings.
  • Main area — the content for the section you are viewing.

Addresses and Back ​

Each console screen has an address in the browser. Back and Forward move through the screens you opened. Reload the page, bookmark it, or paste the address to return to the same project, host, tool page, or list.

An open scan-detail modal is part of that address, on the list you opened it from. Back, ✕, the backdrop, or Escape closes it.

The Nikto logo, the arrow beside it, and All Projects return to the Projects list. On a host, the Hosts breadcrumb returns to the host list. Those go to the parent list; Back returns to the previous screen, which may be somewhere else.

Launch wizards and in-page toggles (for example Hosts / Scans on a tool page) are not separate addresses.

A link whose project cannot be loaded shows Could not open project with the id and the reason, plus the Projects list — it does not look like an empty project.

Core concepts ​

ConceptWhat it is
ProjectA container that groups related targets and their scans. Everything starts here.
HostA target the platform knows about within a project.
ScanA single execution against a target that collects findings, host info, and an activity log.
FindingA vulnerability or issue discovered during a scan.
ReportA curated subset of findings you have chosen to include for delivery or export.
Activity LogA record of every HTTP request the platform made to a target — fully auditable.
JobAn asynchronous unit of work the platform processes in the background.

Your first scan ​

  1. Create a project. On the Projects screen, click New Project, give it a name (for example Production Site Scan) and an optional description, then Create Project. See the Projects guide for details.
  2. Open the project. Click the project card to enter it. The sidebar now shows the project's sections.
  3. Add a host and run a scan. Click New Scan/Import, paste a target URL, click Next, enable the tools you want (Nikto, Crawl, and/or Bustah), then Start Scan. The wizard stays open and shows Creating scans…; Closing this window does not stop scan creation. To launch one tool only, expand Tools in the sidebar, choose Nikto, Crawl, or Bustah, then New Scan. For LFIC, choose Tools → LFIC, then New LFIC Scan. See Scans.
  4. Triage findings. Open Findings to review results. Mark items Reviewed as you go, Add to Report for what matters, filter by severity, and export selected rows.
  5. Check recommendations. Open Recommendations for follow-ups derived from what the scans saw. A few carry an action you can run, such as exporting the full file list of a public cloud storage listing.
  6. Audit activity. Open Logs to see the requests made to the target.

Optional: under Settings → Scan Defaults, set project-wide starting values for new scans (User-Agent, Secret Detection, proxy, and more). Per-host overrides live on each host's Scan Defaults tab.

Next steps ​

Proprietary software. Licensed for use under the End User License Agreement.