Web Application Attack and Audit Framework Anthony Pell 1 min read Jun 13, 2007 w3af, is a Web Application Attack and Audit Framework. It is extended using plugins; the framework and the plugins are fully written in python. Each plugin will add a functionality like xss detection or sql injection exploitation. Prev: Pixy - An Open-Source Vulnerability Scanner for PHP Applications Next: With RHEL 5, Red Hat goes to bat for SELinux