WappaCVElyze by cw
See the technologies behind any site with their versions, colour-coded by known vulnerabilities: current, outdated, end-of-life, vulnerable (CVE) or actively exploited (CISA KEV).
Available on Firefox for Android™Available on Firefox for Android™
Scan the QR code to open this extension in Firefox for Android
Extension Metadata
Screenshots
About this extension
WappaCVElyze identifies the web technologies behind the page you are on — server software, CMS, frameworks, JavaScript libraries — and, unlike a plain technology detector, shows the detected version and whether that version is safe.
Each technology gets a verdict:
• Current — newest release of a maintained cycle, no known CVE
• Outdated — no known CVE, but a newer release exists
• End of life — the release cycle no longer receives fixes
• Vulnerable — a CVE applies to this exact version, with the affected range, CVSS, EPSS exploitation probability and public-exploit flags
• Critical — the CVE is on CISA's Known Exploited Vulnerabilities catalog
Every red row links to the NVD record, the CISA entry and the vendor advisory that confirm it.
Verdicts come from a small database built daily from public sources (NVD, CISA KEV, FIRST EPSS, endoflife.date, Retire.js, Nuclei and Metasploit exploit indexes) and downloaded once a day. Page content is analysed locally and never leaves your browser; the site you visit is never sent anywhere. Privacy policy for every request the extension makes: https://github.com/xZoroo/wappacvelyze/blob/main/PRIVACY.md.
Open source (MIT): https://github.com/xZoroo/wappacvelyze — a command-line scanner with the same verdicts is included.
Each technology gets a verdict:
• Current — newest release of a maintained cycle, no known CVE
• Outdated — no known CVE, but a newer release exists
• End of life — the release cycle no longer receives fixes
• Vulnerable — a CVE applies to this exact version, with the affected range, CVSS, EPSS exploitation probability and public-exploit flags
• Critical — the CVE is on CISA's Known Exploited Vulnerabilities catalog
Every red row links to the NVD record, the CISA entry and the vendor advisory that confirm it.
Verdicts come from a small database built daily from public sources (NVD, CISA KEV, FIRST EPSS, endoflife.date, Retire.js, Nuclei and Metasploit exploit indexes) and downloaded once a day. Page content is analysed locally and never leaves your browser; the site you visit is never sent anywhere. Privacy policy for every request the extension makes: https://github.com/xZoroo/wappacvelyze/blob/main/PRIVACY.md.
Open source (MIT): https://github.com/xZoroo/wappacvelyze — a command-line scanner with the same verdicts is included.
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Access browser tabs
- Access your data for all websites
Optional permissions:
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 0.1.0
- Size
- 8.28 MB
- Last updated
- 5 days ago (Sep 13, 2026)
- Related Categories
- License
- MIT License
- Version History
- Tags
- Add to collection