$ █
10
MODULES
~92%
ACCURACY
0FP*
FALSE POSITIVES
6
PENTEST TOOLS
* soft-404 baseline + content verification
// 10-MODULE SCAN PIPELINE
Every module backed by real tool output or verified HTTP evidence. No guessing, no noise.
Identifies frameworks, CDNs, CMS platforms, and server software from response headers and DOM patterns.
Service detection, version banners, and exposure analysis on database, RDP, and admin ports.
Expired certs, weak ciphers, deprecated TLS 1.0/1.1, missing PFS, self-signed cert detection.
CSP, HSTS, X-Frame-Options, cookie flags (HttpOnly/Secure/SameSite), and smart CORS analysis.
Probes 25+ endpoints — Swagger, GraphQL, Prometheus, actuators, FTP directories, admin panels.
TRACE method detection, HTTPS redirect checks, 6,700+ vulnerability signatures.
Soft-404 baseline detection + content verification eliminates WAF false positives entirely.
Crawls forms and params, injects canaries, confirms only unencoded reflections in HTML/JS context.
SQLi login bypass, default credential testing, JWT weak-secret HMAC cracking against 13 common keys.
Error-based, boolean-based, union-based, and stacked queries — sqlmap with internal fallback.
// DOCUMENTATION
Sign up with your email. New accounts default to the "user" role with a limit of 3 concurrent scans.
From the dashboard, click "New Scan". Enter a target URL and choose Quick (2–5 min) or Comprehensive (10–20 min) mode.
The reports view streams progress in real time across three panels: a process log, a findings feed, and a live radar visualizer.
Once complete, export as PDF, JSON, or CSV — each finding includes CVSS scores, CVE references, and remediation code.
// SUPPORT
Yes. Every module has an internal HTTP-based fallback. nmap, nikto, sqlmap, gobuster, sslscan, and whatweb add significant depth when available, but the scanner runs and produces accurate results without them — verified via baseline soft-404 detection and content checks.
Before probing any path, a random UUID canary request establishes a baseline for what "not found" looks like on the target. Every subsequent finding is compared against this baseline and verified by content — not just an HTTP 200.
Quick mode (2–5 min) covers headers, SSL, core directory checks, and lightweight auth/XSS testing. Comprehensive mode (10–20 min) adds deeper sqlmap levels, expanded wordlists, and broader endpoint discovery.
Quick mode is designed to be safe for production. Comprehensive mode uses higher-intensity payloads — we recommend running it against staging environments first, or during low-traffic windows on production.
Yes — the reports view polls every 2 seconds and attempts an SSE connection for instant updates. You'll see each scan module activate, live findings stream in, and a radar visualization update as vulnerabilities are discovered.
Scan results are stored in your account only. Raw tool output snippets used as evidence are retained for report accuracy but are never shared outside your account and admin oversight.