WebCompScan

The binsec.tool WebCompScan is a free, automated analysis tool for web applications that detects components, libraries, and frameworks, determines their version, and checks them for known security vulnerabilities. It is designed as a quick first-look tool to rapidly gain an initial overview of the technologies in use and potential risks — but it does not replace a full vulnerability scanner or an in-depth application security assessment. The goal of the tool is to quickly and reliably inventory the software building blocks of an application — from JavaScript libraries and frontend frameworks to server-side CMS modules and often overlooked auxiliary libraries — and to derive prioritized action items for developers and security teams.

WebCompScan combines multiple detection strategies: evaluation of HTTP headers and HTML metadata, analysis of loaded JavaScript and CSS resources, as well as heuristic signatures for known components. Detected components are enriched with version information (where available) and cross-checked against publicly accessible vulnerability databases to identify known CVEs and risk information. By identifying the tools and technologies running in the background of a web application, WebCompScan also enables the planning of more targeted attack and testing scenarios — for example, by prioritizing specific libraries, framework versions, or admin interfaces.

WebCompScan primarily detects publicly accessible or client-side loaded components. Dynamically loaded, heavily obfuscated, or server-internal dependencies are harder to capture and may result in gaps in the inventory. Missing or intentionally removed metadata (such as minified/concatenated bundles or missing source maps) can reduce version detection accuracy. For complete assessments, WebCompScan should be combined with internal scans and manual analysis.

WebCompScan thus quickly produces a usable inventory of web components and identifies known risks — a pragmatic tool for mapping the attack surface of modern web applications, particularly well-suited for rapid assessments and the planning of targeted follow-up analyses.

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808