W3af is an open source web application security scanner designed to identify and exploit web application vulnerabilities. It is a powerful and highly configurable tool that can detect a wide range of web application threats, including SQL injection, cross-site scripting, file inclusion, and other common web application vulnerabilities. W3af can also help security professionals identify misconfigurations in web applications that could lead to a security breach. W3af can be used to detect and exploit vulnerabilities in web applications running on any web server and is compatible with Linux, Windows and Mac OS X.
Discontinued The extension is no longer being developed since 2010 and is not compatible with Firefox 57 and later versions. It still works in XUL-based Firefox forks such as https://alternativeapp.info/software/waterfox/ and https://alternativeapp.info/software/palemoon/.
Skipfish is no longer maintained. The latest version, 2.10 beta, released in December 2012, can still be downloaded from Google Code Archive.