Skip to content

User Guide ​

How to use the Nikto Platform console day to day. If you are new to the product, read Getting Started first.

Organize ​

  • Projects — create, edit, and organize projects.
  • Hosts — import, manage targets, List view / Tile view, live scan activity, Sitemap, Target Config, Scan Defaults.

Scan ​

  • Scans — Tools (host-first), New Scan wizard, one scan-detail modal, Speed limit, Pause All / Resume All, Active Jobs (All / Running / Paused, all projects).
  • Scan options — shared Options / Throttling & Limits, Nikto modules, MS10-070, JWT.
  • Scan Scope & Address Tiers — public / private / local address tiers; what a scan may follow; platform self-block.
  • Web Crawler — Standard vs Headless Browser engines (or both), scope, technologies, screenshot, recommendations.
  • Bustah — content-discovery sweeps, crawl/Nikto seeding, results tree/table with directory controls and state chips, Add to report.
  • Cloud Storage Listings — public S3, S3-compatible, and Azure Blob Storage listings; Export full file list.
  • HTTP/3 (QUIC) — Nikto / LFIC / Bustah over QUIC; crawler excluded; Alt-Svc workflow.
  • LFIC — LFI Commander; New LFIC Scan from Tools → LFIC, or the host LFIC tab.

Results ​

  • Findings — triage with reviewed/unreviewed, grouped technologies, scoped search, truncation banner, secret detection, TLS cert findings (including wildcard), Tomcat Manager when access-restricted, JWT (one per token), outdated server software, request-capture notes, Loaded By provenance.
  • Recommendations — host follow-ups from Nikto and Crawl; Export full file list for open cloud listings.
  • Report — curated items and evidence; selective removal; export HTML, Markdown, or JSON.
  • Exporting Findings — save selected findings to CSV or JSON.
  • Logs — per-project activity log; global app log via Status.

Operate ​

  • Docker Deployment — install the stack, optional Chromium for Headless crawls, license file.
  • Host Commands — every command run on the Docker host: start/stop, update, backup/restore, support bundle, sign-in recovery.
  • Status — /nikto-diag diagnostics (build, database, storage, live app log).
  • Settings — tabbed Connection & Limits, Scan Defaults, Bustah, LFIC, Appearance, License; proxies, throttle, request timeout, 429 / slow-target backoff, wordlist/fileset libraries.
  • Accessibility — keyboard navigation, skip link, screen-reader announcements, Theme (light, dark, retro terminal) and Motion preferences.
  • Operator Login — first login and setup code, changing your password, locked out, forgotten username, AUTH=off.
  • License — install, replace, and understand license states; new work vs in-flight scans; installing from a license file.

Report an Issue ​

Report an issue sits at the bottom of the left sidebar, below Global Settings. It opens a short list of issue types:

  • Bug
  • False positive
  • Missed finding
  • Install or update problem
  • Feature request

Each choice opens a new GitHub issue form on the support repository in a new browser tab. You need access to that repository to file the issue.

The form's version field is filled in with the API and UI builds you are running, for example API v0.1.0 (abc123def456) · UI v0.1.0 (abc123def456). The dialog shows this exact string before you choose. If the console could not get the API version, the string says API version unavailable. Nothing is sent automatically: the version string leaves your machine only when you click an issue type, as part of the GitHub link, and the issue is filed only when you submit the form on GitHub.

Support bundle ​

For an install, update, or "it stopped working" problem, attach a support bundle to the issue. Run the command on the machine that runs the platform:

bash
nikto-launcher support-bundle

It writes support-bundle-YYYYMMDD-HHMMSS.zip.

The file goes to your Downloads folder (~/Downloads, or $XDG_DOWNLOAD_DIR on Linux), or to the current directory if there is no Downloads folder. Add --out DIR to choose another existing directory. The command prints "Support bundle written:" and the file's full path. The file is readable only by your user account.

A bundle contains:

  • the Docker and Docker Compose versions and the list of containers
  • the diagnostics from the Status page, as text
  • your .env settings, with passwords, tokens, keys and your GitHub username replaced by <redacted> (the database username stays visible)
  • the last 2,000 log lines of each container

It never contains scan results, database contents, backups, the database password file (secrets/db_password), or your license file.

Passwords, tokens, session cookies, sign-in links, setup codes, private keys and credentials inside URLs are removed from the logs and diagnostics. Anything shaped like a setup code (XXXX-XXXX-XXXX-XXXX) is removed, even when it is something else.

The logs still contain the hostnames and URLs of your scan targets. Nothing is uploaded: open the file and review it before you attach it.

  • --no-logs leaves the logs out.
  • --tail N keeps the last N lines of each container's log instead of 2,000.

If the API is not running, the bundle is still written, and diag.txt inside it says why the diagnostics are missing.

Proprietary software. Licensed for use under the End User License Agreement.