View Issue Details

IDProjectCategoryView StatusLast Update
0009874Kali LinuxNew Tool Requestspublic2026-09-30 16:10
Reporterj3ssie Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
Summary0009874: vigolium: native web application vulnerability scanner
Description

Name: Vigolium
Version: 0.5.1 (upstream tag v0.5.1)
Homepage: https://vigolium.com
Source and release: https://github.com/vigolium/vigolium/releases/tag/v0.5.1
Downloads:

Description:
Vigolium is a Go command-line tool for authorized web application security assessment. It includes native active and passive analysis modules, can analyze HTTP traffic supplied by the user (including Burp exports), stores evidence in project-scoped SQLite or PostgreSQL databases, and provides a REST API. Native scans and analysis run locally; an optional AI integration is available. The package does not install scanner engines as services or start a daemon.

Runtime package dependencies: ca-certificates, libc6, libstdc++6, zlib1g. Chromium is optional for browser-based crawling; Git is useful for repository/template operations.

Similar tools: Nuclei, OWASP ZAP, Nikto, Wapiti and ffuf provide related web security testing capabilities.

Activity: The project began in March 2026 and is actively maintained. Version 0.5.1 was released on 2026-09-24. Source, changelog, build instructions and issue tracker are available at https://github.com/vigolium/vigolium.

How to install/test the upstream binary package:

  1. Download the package for the target architecture and debian-checksums.txt from the v0.5.1 release page.
  2. Verify the checksum with: sha256sum -c debian-checksums.txt
  3. Install on amd64 with: sudo apt install ./vigolium_0.5.1_amd64.deb (use the arm64 package on arm64).
  4. Confirm installation with: vigolium version and vigolium --help.

How to build from source: the project documents Go 1.27+ and Bun 1.3.11+ as build prerequisites; run make build from the tagged source checkout. See the README and build documentation in the source repository.

Packaged status: upstream publishes amd64 and arm64 binary .deb files. I installed, exercised harmless CLI/database initialization commands, and removed each package successfully in clean Kali rolling 2026.3 containers for amd64 and arm64. The package is not currently in the Kali archive. These upstream binary .deb files are generated from the release binaries; the source repository does not yet contain a Debian packaging (debian/) directory or Debian-policy source package. I am requesting review and guidance for adding Vigolium to Kali, including any source packaging and policy work required by the maintainers.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-09-30 16:10 j3ssie New Issue