Wapiti allows you to audit the security of your web applications. It performs
"black-box" scans, i.e. it does not study the source code of the application
but will scans the web pages of the deployed web app, looking for scripts and
forms where it can inject data. Once it gets this list, Wapiti acts like a
fuzzer, injecting payloads to see if a script is vulnerable.