# Nikto: Web Server Vulnerability Scanner in Perl

> Nikto is an open-source web server scanner written in Perl that checks hosts for dangerous files, outdated server software, and HTTP configuration issues. It runs from a clone of the repository or as a Docker container, and its test database supports a mini-DSL for writing custom matchers.

**sullo/nikto** — Nikto web server scanner

- Repository: https://github.com/sullo/nikto
- Stars: 10,747 · Forks: 1,462
- Language: Perl
- License: NOASSERTION
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/sullo-nikto

## What Nikto Scans and Who It Is For

Nikto checks a web server for a range of known issues: potentially dangerous files and CGI scripts, server software that is out of date, and HTTP headers or configurations that signal a security weakness. The scanner is intended for authorized security assessments, whether run by a system owner against their own infrastructure or by a penetration tester with written permission to test a target.

The tool has been maintained since 2001 and its documentation lives at https://cirt.net/Nikto2. It is not an application-layer fuzzer and does not perform authenticated testing of web application logic. Its strength is breadth across known server-level issues rather than depth into application behavior.

## How Nikto Sends Requests and Matches Responses

Nikto issues HTTP requests to the target and evaluates responses using its test database. The database supports a mini-DSL with four matcher types: BODY: and !BODY: match or exclude content in the response body, HEADER: and !HEADER: match or exclude HTTP header content, COOKIE: and !COOKIE: match or exclude cookie content, and CODE: and !CODE: match or exclude HTTP status codes. Multiple conditions can be combined with && (AND logic). An example from the README illustrates this:

```
BODY:login&&!BODY:logout&&HEADER:X-Powered-By&&COOKIE:sessionid
```

This expression matches only when the response body contains "login", does not contain "logout", the headers include X-Powered-By, and a cookie named sessionid is present. The DSL makes it possible to write precise tests that avoid false positives from partial matches.

The underlying HTTP library is LibWhisker, which ships under its own separate license from Nikto's GPL-3.0 code. The scanner also supports IPv6 checking via the -check6 flag, which connects to ipv6.google.com by default.

## Installing Nikto and Running a First Scan

The fastest way to start is to clone the repository and run the main script directly:

```bash
git clone https://github.com/sullo/nikto
cd nikto/program
./nikto.pl -h http://www.example.com
```

If the script is not yet executable, the README offers an alternative:

```bash
perl nikto.pl -h http://www.example.com
```

For users who prefer Docker, the image is available from both Docker Hub and GitHub Container Registry:

```bash
docker pull hackllc/nikto:latest
```

The Docker image is built on Alpine Linux 3.23.3 and installs the required Perl modules: perl-net-ssleay, perl-json, perl-io-socket-ssl, perl-xml-writer, perl-mime-base64, and perl-xml-libxml. To save a report from a Docker run, the README recommends mounting the current directory as a volume and writing output to /tmp:

```bash
docker run --rm -v $(pwd):/tmp hackllc/nikto -h http://www.example.com -o /tmp/out.json
```

The -o flag accepts a path; the output format is inferred from the extension.

## Key Command-Line Options

Nikto exposes a wide set of flags. The -h flag sets the target host. The -Cgidirs flag controls which CGI directories to scan, accepting none, all, or a space-separated list of paths. The -config flag points to an alternate configuration file, useful when overriding the defaults in nikto.conf. The -Add-header flag injects custom HTTP headers into every request and can be specified multiple times.

The -ask flag controls whether Nikto prompts to submit database updates: yes asks per item (the default), no suppresses prompts and sending, and auto sends without asking. For scripted or automated runs, setting -ask no prevents interactive prompts from blocking execution.

The full option list is available by running:

```bash
./nikto.pl -h
```

Full documentation is hosted on the GitHub wiki at https://github.com/sullo/nikto/wiki.

## Limitations of a Database-Driven Scanner

Nikto's coverage is bounded by its test database. It identifies what the database knows about. A custom-built web application with its own logic flaws will not appear in Nikto's output. The database files are also not licensed under the GPL; the licensing terms at https://cirt.net/Nikto-Licensing restrict redistribution outside the official package and prohibit commercial redistribution without a separate agreement. This matters for anyone packaging Nikto inside a commercial product.

Nikto does not authenticate to web applications by default. It checks for server-level and path-level issues, not issues that require a logged-in session. Tools designed for authenticated application testing, such as OWASP ZAP or Burp Suite, cover that layer instead.

The scanner also generates traffic patterns that most intrusion detection systems will recognize. It is not designed for stealth, and running it against a production system without a maintenance window or IDS exception will likely trigger alerts.

## Nikto versus OWASP ZAP

OWASP ZAP is a Java-based web application security scanner maintained by the OWASP Foundation. Where Nikto is a Perl script run from the command line against a target URL, ZAP provides a full graphical interface (and a headless mode) with support for authenticated crawling, active scanning, and passive analysis of proxied traffic. ZAP can intercept browser sessions and scan what it observes, which makes it more capable for testing authenticated application flows.

Nikto is faster to invoke for a quick server-level check: clone, run, done. ZAP requires more setup and is better suited to longer engagements where a tester needs to map an application's full attack surface. For a first pass against a new server to spot obvious misconfiguration and known vulnerable paths, Nikto covers that job with fewer moving parts.

## Licensing, Maintenance, and Version History

The Nikto codebase is licensed under GPL-3.0. The LibWhisker HTTP library ships under a separate license documented in COPYING.LibWhisker. The test database files are restricted to use within the official Nikto package; commercial use requires a license from https://cirt.net/Nikto-Licensing.

The project has been maintained by Chris Sullo since 2001. The most recent release is 2.6.1, published on 2026-07-31. The last push to the repository was on 2026-09-25, indicating ongoing maintenance. Release 2.6.0 introduced the COOKIE: matcher; 2.5.0 was released in December 2023. The changelog is not included in the repository files provided, but the wiki and https://cirt.net/Nikto2 are the primary references for version-specific changes.

## Conclusion

Nikto is appropriate for security engineers and penetration testers who need a fast, scriptable scanner to check web servers during authorized assessments. It is not a replacement for tools that perform deep application-layer testing, and its database files carry a separate license that restricts redistribution outside the official package. Before running, confirm that you have written authorization to scan the target, and verify that your Nikto installation is on a recent release since the test database is updated with each version.

## FAQ

### What is a Nikto scan?

A Nikto scan is a server-level check that sends HTTP requests to a target host and evaluates the responses against a test database of known dangerous paths, outdated software signatures, and HTTP configuration weaknesses.

### How do I use Nikto in Kali Linux?

Clone the repository with git clone https://github.com/sullo/nikto, navigate to the program/ directory, and run ./nikto.pl -h http://target with the target URL. Kali Linux also includes packages for Perl and the required Perl modules.

### How do I install Nikto?

Run git clone https://github.com/sullo/nikto to get the source. Alternatively, pull the Docker image with docker pull hackllc/nikto:latest and run the container without any local Perl installation.

## Sources

- [Issues](https://github.com/sullo/nikto/issues)
- [README](https://github.com/sullo/nikto/blob/main/README.md)
- [Releases](https://github.com/sullo/nikto/releases)
- [sullo/nikto on GitHub](https://github.com/sullo/nikto)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/sullo-nikto
