SekuScan Start evaluation

Benchmarks

Public benchmark results.

Raw results are linked at the foot of the page.

Results

BenchmarkResult
WAVSEP — positive cases1 210 / 1 210
WAVSEP — negative cases38 / 44 silent
Google Security Crawl Maze85 / 85 scored · 6 excluded
SekuScan crawler traps ours10 / 10
OWASP VulnerableApp102 / 154 · 66.2%

WAVSEP

zaproxy/wavsep, the ZAP team’s fork of sectooladdict/wavsep

Positive cases

CategoryDetected
LFI816 / 816
SQLi135 / 135
RFI108 / 108
Reflected XSS91 / 91
Open redirect60 / 60
Total1 210 / 1 210

Negative cases

ResultCases
Stayed quiet38
Outside supported scope4
Answer key disputed1
False positive1
Total44
  • 11 further cases are marked OBSOLETE in the corpus and were not run.
  • The false positive was an LFI look-alike, reported as traversal.
  • The disputed case: the target fetched a URL we supplied and our callback fired, which is SSRF. WAVSEP scores that case for remote file inclusion, which does not occur. It is counted against us anyway.

71,966 requests · ≈ 4 h*

Google Security Crawl Maze

google/security-crawl-maze

85 / 85 scored cases found.

  • 6 cases excluded: the deployment does not serve them (Angular, Polymer and React framework routes). Excluded from the denominator, not counted as misses.

230 requests · ≈ 1 min*

OWASP VulnerableApp

SasanLabs/VulnerableApp

102 / 154 · 66.2%

  • 52 expected findings missed.
  • Graded by the project’s own /scanner/benchmark harness.
  • 206 findings sent, 101 unmatched by the harness.

graded by the corpus harness*

Selected vulhub targets

vulhub/vulhub

Selected targets only; no aggregate score.

CVE / issueSoftwareCheck
CVE-2018-7600 “Drupalgeddon2”Drupalinjection/drupal_render
CVE-2021-22205GitLab (ExifTool)injection/gitlab_exiftool
S2-045, S2-059, S2-061Apache Struts 2injection/struts_ognl
CVE-2024-27956WordPress Automaticinjection/wp_automatic_sqli
CVE-2026-63030WordPress (batch)injection/wp_batch_sqli
CVE-2024-6624WordPress JSON API Userauth/wp_json_api_user_privesc
CVE-2020-25213WP File Managerupload/unauth_connector
Magento 2.2 SQL injectionMagentoinjection/sqli

Raw results

* Every run above was measured on 2026-09-09 against engine a2b55e7 with a clean tree; each JSON below carries its own provenance stamp, written by the harness rather than typed here. Durations marked ≈ are derived, not recorded: the harness did not time these runs, so the figure is the request count over the median throughput of 4.8 operations per second measured across 47 other runs. The harness records wall-clock time from now on, and these will be replaced by measured values on the next run.