paranoic-scan
Web security assessment tool for self-auditing web applications. Based on Paranoic Scan 1.7 (2014) by Doddy Hackman - modernized to Python with updated security patterns.
Note: This tool is based on a 2014 Perl tool and is intended for authorized security testing on systems you own or have permission to test. The vulnerability detection techniques may be outdated for modern applications with WAF/IPS protection.
Install
pip install paranoic-scan
Usage
# Find admin panels
paranoic-scan panel http://example.com
# Scan for SQL injection
paranoic-scan sqli http://example.com/page?id=1
# Scan for LFI
paranoic-scan lfi http://example.com/view?file=
# Scan for XSS
paranoic-scan xss http://example.com/search?q=
# Try admin login bypass
paranoic-scan bypass http://example.com/admin/login
# Find directory listings
paranoic-scan paths http://example.com
# HTTP fingerprinting
paranoic-scan httpfinger http://example.com
# Port scan
paranoic-scan portscan 192.168.1.1
# MD5 encode
paranoic-scan md5 "password"
# MD5 crack
paranoic-scan crack 098f6bcd4621d373cade4e832627b4f6
# Encoder utilities
paranoic-scan encode b64 "text"
paranoic-scan encode hex "text"
paranoic-scan encode url "text"
paranoic-scan encode bin "text"
paranoic-scan encode ascii "text"
CLI
paranoic-scan --help
API
from paranoic_scan import (
scan_panel,
scan_sqli,
scan_lfi,
scan_xss,
encode_md5,
)
# Find admin panels
panels = scan_panel("http://example.com", count=5)
# Scan for SQLi
is_vulnerable = scan_sqli("http://example.com?id=1")
# Encode MD5
hash = encode_md5("password")
Development
git clone https://github.com/daedalus/paranoic-scan.git
cd paranoic-scan
pip install -e ".[test]"
# run tests
pytest
# format
ruff format src/ tests/
# lint
ruff check src/ tests/
# type check
mypy src/
Disclaimer
This tool is provided for authorized security testing only. Use only on systems you own or have explicit written permission to test. The author is not responsible for any misuse or damage caused by this tool.
Metadata
Release files for paranoic-scan 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| paranoic_scan-0.1.0.tar.gz | 10.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| paranoic_scan-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.1 kB
Release files / paranoic_scan-0.1.0.tar.gz
| Download URL | paranoic_scan-0.1.0.tar.gz |
|---|---|
| Size | 10.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ecc6204c79f0d4c237d6cc7997df3bcc42bb6c94daa56ae41bd2fd6d025e3cf4
|
|
BLAKE2b-256 checksum How to use checksums |
8eca084ee01b99279257d5e9195c416728bb8aaebb329f5592c464f0b9a1255a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 7, 2026.
Transparency logRelease files / paranoic_scan-0.1.0-py3-none-any.whl
| Download URL | paranoic_scan-0.1.0-py3-none-any.whl |
|---|---|
| Size | 11.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0661acaa03b228d8b45cb75b2181aa70a405558cd1bbb2a1f792057d5a3726eb
|
|
BLAKE2b-256 checksum How to use checksums |
9b31863fec5ea27c30a27708accd30f35ffa7184c1154f7607ef0a7464715a1a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 7, 2026.
Transparency log