All projects
Securitylive

SpencerWeb

Web vulnerability scanner covering SQLi, XSS, CSRF, SSL issues, open ports, and exposed files, mapped to the OWASP Top 10. Ships a live dashboard and auto-generated PDF reports. Built as my final project.

PythonNodeOWASPReportLab
SpencerWeb dashboard new-scan form: URL target field and Fast/Standard/Deep scan mode selection

the problem

Small businesses and student projects rarely get a real security audit before going live -- commercial scanners are expensive or built for enterprise teams, and free tools tend to flood a report with false positives instead of ranked, actionable findings.

approach

Built as my Computer Engineering final project (TA, Politeknik Negeri Medan), SpencerWeb runs 10 scanning modules end to end: a crawler maps the site and every form first, then passive checks (headers, SSL/TLS, exposed files, CMS/plugin fingerprinting) run alongside active checks (SQL injection with error/boolean/time-based detection, reflected and stored XSS, CSRF token analysis, port reconnaissance). Findings map directly to OWASP Top 10 categories and get scored with CVSS, then compiled into a client-ready PDF.

architecture

CLI scanner (Python)

10 modules from deep crawl through active exploitation checks, runnable standalone for CI or headless audits.

Web dashboard (Node/Express)

Real-time scan progress, historical scan comparison, and a visual report -- the same engine, a UI on top.

PDF reporting (ReportLab)

Auto-generates a professional, partner-ready report from the same scan data the dashboard shows live.

SQL injection module

The one module explicitly marked "verified" in its own docs: error-based, boolean-based, and time-based detection, not just pattern matching on response text.