Open-source project
baihengaead/wlan-sec-test-tool avatar
baihengaead/wlan-sec-test-tool

wlan-sec-test-tool: Python GUI for WPA/WPA2/WPA3 WiFi Security Testing

无线网络安全测试工具,支持测试WPA/WPA2/WPA3、多开并发、自动化测试连接,需自定义密码本

4,232 stars518 forksPythonMIT

At a glance

What is it?
wlan-sec-test-tool is a Python GUI application that tests whether a WPA, WPA2, or WPA3 network can be accessed with passwords from a custom list. It targets authorized penetration testers and security researchers studying wireless network vulnerabilities.
Who is it for?
wlan-sec-test-tool is a practical choice for security researchers or authorized penetration testers who need a GUI-based live connection tester for WPA/WPA2/WPA3 networks on Windows, Linux, or macOS. It is not a substitute for offline hash-based tools when speed matters and a handshake capture is possible.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 123 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What wlan-sec-test-tool Tests and Who Should Use It

wlan-sec-test-tool is a Python-based wireless network security testing tool with a graphical interface. It works by attempting to connect to a target WiFi network using passwords drawn from a custom text file, one by one, to determine whether the network is protected by a weak or commonly used password. The tool tests against WPA, WPAPSK, WPA2, WPA2PSK, WPA3, and WPA3SAE security protocols.

The README states explicitly that the tool is for authorized penetration testing and wireless security education only. Legitimate use cases listed in the documentation are: academic research and security courses in controlled lab or classroom environments, authorized penetration testing with written permission from the network owner, and testing of personal equipment the tester fully owns and controls. Any use outside these boundaries is prohibited under the project's terms.

The project version is 1.3.1 as declared in pyproject.toml. The license is MIT.

Supported Protocols and Multi-Instance Concurrent Testing

The tool supports WPA, WPAPSK, WPA2, WPA2PSK, WPA3, and WPA3SAE. This covers the full range of currently deployed WPA-family protocols, including the SAE (Simultaneous Authentication of Equals) handshake used in WPA3.

The multi-instance concurrent testing feature allows several test sessions to run at the same time. This requires at least two wireless network adapters installed and working on the same PC. The README describes this as one of the core operating modes alongside automatic mode, which scans for available WiFi networks and tests connections automatically without manual target selection.

The tool has two entry points: a GUI (wlan_sec_test_tool_gui.py) and a command-line interface (wlan_sec_test_tool_cli.py). The pyproject.toml defines two CLI commands: `wlan-sec-test-tool-cli` and the shorter alias `wstt`, both pointing to the cli module's main function.

Setting Up the Password List and Running a Test

The tool does not include a password list. Users must supply one. The default password file path is:

cmd
./passwords.txt

Each line in this file is one candidate password:

txt
password1
password2
password3

For targeted testing across multiple known networks, a JSON dictionary file can be used instead:

cmd
./dict/pwdict.json

This file maps network names (SSIDs) to known or candidate passwords:

json
[
    {
        "ssid":"wifi_1",
        "pwd":"password1"
    },
    {
        "ssid":"wifi_2",
        "pwd":"password2"
    }
]

Test results are written to the log directory at:

cmd
./log

The README notes that users should test their wireless adapter's scan and connection delays before running tests, then set the scan time and connection time in the UI to match what the adapter needs to complete each operation successfully. Getting these timing values wrong produces false negatives where the tool moves on before the connection attempt finishes.

Platform-Specific Dependencies and Installation Requirements

The tool requires Python 3.11 or later; the README recommends version 3.11.9 and the pyproject.toml sets `requires-python = ">=3.11"`.

Dependencies differ by operating system. On Windows and Linux, the tool uses the pywifi library (a fork maintained at baihengaead/pywifi) alongside PySide6 for the GUI. On macOS, the pywifi library is not used; WiFi operations go through the bundled wifi_macos.py module instead, which uses PySide6 and pyperclip.

The requirements.txt at the repository root lists the core dependencies:

code
PySide6>=6.7.2
pyperclip>=1.9.0
pyinstaller>=6.9.0

PyInstaller is included for packaging the application into a standalone executable. Separate requirements files exist for each platform: requirements_linux.txt, requirements_macos.txt, and requirements_win.txt.

Supported platforms are Windows 10 and later, Ubuntu 22.04 and later (marked experimental), other Linux distributions with Python 3.11+ (marked experimental), and macOS 12 (Monterey) and later. The Linux support is experimental, which means the tool may not function correctly with all Linux wireless adapters or pywifi driver bindings.

Limitations and Cases Where This Tool Is the Wrong Choice

The tool performs live connection attempts over the air. Each password candidate requires a full connection cycle: scan, connect attempt, result, and timeout. The timing between attempts depends on the wireless adapter's response latency, which the user must calibrate manually. Large password lists take a long time to exhaust at live-connection speeds.

The README does not document error handling for cases where the adapter drops out mid-test, where the target network disappears, or where the operating system's network manager interferes with low-level WiFi operations. On Linux, driver and NetworkManager conflicts with pywifi are a known class of problem in similar tools, and the experimental label on Linux support reflects this. The README does not document how to disable or work around NetworkManager before running the tool.

The tool has no built-in password list generation. It cannot create word lists, apply rules, or mutate base words the way dedicated password recovery tools do. Users who need a tailored list must generate one separately and place it at ./passwords.txt before starting a session.

For environments where the wireless handshake can be captured as a file, offline tools work much faster because they do not wait for each live connection attempt. This tool's live-connection approach is appropriate for scenarios where capturing a handshake first is not practical, or for demonstrating the risk posed by a specific known weak password on a specific network. It is not designed for testing large password spaces at speed.

wlan-sec-test-tool vs. Aircrack-ng for WiFi Security Assessment

Aircrack-ng is a widely used open-source WiFi security auditing suite that captures WPA handshakes using a monitor-mode adapter and then cracks the captured hash offline against a word list. The core difference from wlan-sec-test-tool is the attack model: aircrack-ng works entirely offline after capturing the four-way handshake, so it is not limited by live connection timing and can test millions of candidates per second depending on hardware. wlan-sec-test-tool tests live connections one at a time, bounded by network response latency.

Aircrack-ng requires a wireless adapter capable of monitor mode and packet injection, which not all adapters support. wlan-sec-test-tool uses the standard connection API (through pywifi or the macOS WiFi module) and does not require monitor mode, making it accessible on hardware that cannot do packet injection.

For an authorized assessment where speed matters and a handshake capture is feasible, aircrack-ng is the more practical tool. wlan-sec-test-tool is the simpler choice for testing a specific known-password hypothesis on hardware that lacks monitor mode capability.

Maintenance Status and Compliance Notices

The last push to the repository was on 2026-06-03. The project is under the MIT license. The repository has no GitHub releases; the current version 1.3.1 is declared in pyproject.toml.

The README contains an extended compliance notice that was added in response to unauthorized redistribution of the tool on social media platforms. The notice states that any redistribution that removes the MIT license text or the disclaimer is a violation of the terms. The project maintainer has requested that violating redistributions be taken down and that users report them through the repository's Issues page.

For teams incorporating this tool into an authorized security assessment workflow, the compliance notice is a reminder to keep the original license and disclaimer intact in any documentation or toolkit that includes the tool. The README documents the legal framework under which authorized use is permitted: academic research, authorized penetration testing with written consent, and personal device testing.

Editorial conclusion

wlan-sec-test-tool is a practical choice for security researchers or authorized penetration testers who need a GUI-based live connection tester for WPA/WPA2/WPA3 networks on Windows, Linux, or macOS. It is not a substitute for offline hash-based tools when speed matters and a handshake capture is possible. Before using it, confirm you hold written authorization for the network being tested, assemble a password list tailored to your assessment scope, and verify that your wireless adapter is recognized by pywifi on your platform.

Frequently asked questions

Does wlan-sec-test-tool work on macOS?

Yes. The tool supports macOS 12 (Monterey) and later. On macOS it uses a built-in wifi_macos.py module instead of the pywifi library used on Windows and Linux, along with PySide6 and pyperclip for the GUI.

Does wlan-sec-test-tool include a password list?

No. The tool requires users to provide their own password list at ./passwords.txt (one password per line) or a JSON dictionary at ./dict/pwdict.json that maps SSIDs to candidate passwords. No default word list is bundled.

What Python version does wlan-sec-test-tool require?

The project requires Python 3.11 or later. The README recommends version 3.11.9, and the pyproject.toml sets the minimum at Python 3.11.

Official sources

  1. baihengaead/wlan-sec-test-tool on GitHub
  2. Issues
  3. License: MIT
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/baihengaead-wlan-sec-test-tool.svg)](https://hysenlabs.com/projects/baihengaead-wlan-sec-test-tool)