The SQL Injection Detection Accuracy of Web Application Scanners:

The current information is based on the results of the *2011* benchmark (excpet for entries marked as updated or new )

Last updated: 27/08/2012, Currently compares 52 scanners
Sorted in a descending order according to the scanner sql injection detection ratio and product name.
Hint: click the version link to get more information about each scanner evaluation, and the product name to get detailed information on the product.

Unified List   Commercial Scanners   Free / Open Source Scanners


Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
sqlmap1.0sqlmap developers100.00% Detection Rate
0.00% False Positives
(136/136)
(0/10)
2
arachni0.4.0.3Tasos Laskos100.00% Detection Rate
50.00% False Positives
(136/136)
(5/10)
2
IronWASP0.9.1.0Lavakumar Kuppan100.00% Detection Rate
50.00% False Positives
(136/136)
(5/10)
2
Syhunt Mini (Sandcat Mini)4.4.3.0Syhunt100.00% Detection Rate
50.00% False Positives
(136/136)
(5/10)
2
Wapiti2.2.1OWASP100.00% Detection Rate
50.00% False Positives
(136/136)
(5/10)
3
Andiparos1.0.6Compass Security AG77.21% Detection Rate
40.00% False Positives
(105/136)
(4/10)
3
Paros Proxy3.2.13MileSCAN Technologies77.21% Detection Rate
40.00% False Positives
(105/136)
(4/10)
4
Vega1.0Subgraph75.74% Detection Rate
0.00% False Positives
(103/136)
(0/10)
5
ZAP1.4.0.1OWASP75.74% Detection Rate
50.00% False Positives
(103/136)
(5/10)
6
Netsparker Community Edition1.7.2.13Mavituna Security70.59% Detection Rate
30.00% False Positives
(96/136)
(3/10)
7
Watobo0.9.8Andreas Schmidt65.44% Detection Rate
30.00% False Positives
(89/136)
(3/10)
8
W3AF1.2W3AF developers59.56% Detection Rate
30.00% False Positives
(81/136)
(3/10)
9
Sandcat Free Edition4.0.0.1Syhunt58.82% Detection Rate
20.00% False Positives
(80/136)
(2/10)
10
Oedipus1.8.1Jordan Del Grande58.82% Detection Rate
40.00% False Positives
(80/136)
(4/10)
11
WebSecurify (Opensource Version)0.9GNU Citizen58.82% Detection Rate
50.00% False Positives
(80/136)
(5/10)
12
ProxyStrike2.2Edge Security52.21% Detection Rate
0.00% False Positives
(71/136)
(0/10)
13
PowerFuzzer1.0Marcin Kozlowski51.47% Detection Rate
40.00% False Positives
(70/136)
(4/10)
14
WebCruiser Free Edition2.4.2Janus Security50.74% Detection Rate
0.00% False Positives
(69/136)
(0/10)
15
Gamja1.6Sanghun Jeon50.00% Detection Rate
80.00% False Positives
(68/136)
(8/10)
16
WSTool0.14001Kim Young-il45.59% Detection Rate
40.00% False Positives
(62/136)
(4/10)
17
Grendel Scan1.0David Byrne42.65% Detection Rate
50.00% False Positives
(58/136)
(5/10)
18
SkipFish2.07Michal Zalewski - Google40.44% Detection Rate
0.00% False Positives
(55/136)
(0/10)
19
safe3wvs (limited free edition)10.1Safe3 Network Center40.44% Detection Rate
30.00% False Positives
(55/136)
(3/10)
20
Damn Small SQLi Scanner (DSSS)0.1hMiroslav Stampar39.71% Detection Rate
20.00% False Positives
(54/136)
(2/10)
21
JSky Free Edition1.0.0NoSec38.24% Detection Rate
20.00% False Positives
(52/136)
(2/10)
22
SQLiX1.0OWASP37.50% Detection Rate
20.00% False Positives
(51/136)
(2/10)
23
Mini MySqlat0r0.5SCRT Information Security26.47% Detection Rate
0.00% False Positives
(36/136)
(0/10)
24
Uber Web Security Scanner0.0.2Levent Kayan & Illuminatus21.32% Detection Rate
40.00% False Positives
(29/136)
(4/10)
25
Secubat0.5Stefan Kals18.38% Detection Rate
70.00% False Positives
(25/136)
(7/10)
26
Grabber0.1Romain Gaucher15.44% Detection Rate
20.00% False Positives
(21/136)
(2/10)
27
Scrawlr1.0HP Application Security Center13.24% Detection Rate
0.00% False Positives
(18/136)
(0/10)
28
aidSQL02062011Lynxec11.76% Detection Rate
0.00% False Positives
(16/136)
(0/10)
29
iScan0.1Simone Margaritelli0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
LoverBoy1.0Ashaman Boyd0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
openAcunetix0.1John Martinelli0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
Priamos1.0Yigit Aktan0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
SQID (SQL Injection Digger)0.3Metaeye Security Group0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
VulnDetector0.0.2Brad Cable0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
Web Injection Scanner (WIS)0.4netXeyes0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)
29
Xcobra0.2Taras Ivashchenko0.00% Detection Rate
0.00% False Positives
(0/136)
(0/10)

Copyright © 2012 by Shay Chen (sectooladdict). All rights reserved.
Click here to learn how this information may be published or reused.