Documentation
Everything Vulnscape can do and how to use it — scanners, Vulnscape AI, leads, on-demand monitoring, reports, team and safeguards. Authorized security testing only.
Vulnscape checks websites, apps, CRMs and code — especially ones built with AI tools — for vulnerabilities and mistakes, big or small. Deterministic scanners gather evidence; Vulnscape AI (powered by Claude) turns that evidence into severity-scored findings with copy-paste remediation and an aggregate risk score (0–100).
Typical flow:
/app/scan/new.The product console is at /app. Pricing, marketing and this documentation are public.
After sign-in, the left navigation covers:
A global Vulnscape AI assistant bar sits in the console footer for portfolio-level questions. Each scan also has its own chat panel.
Admins can assign or override plans and create time-limited vouch accounts from /app/admin/users.
Where: New scan → Code.
Paste source or upload a file. A regex pre-pass flags SQL injection sinks, XSS sinks, hard-coded secrets/credentials, weak crypto and dangerous functions. Vulnscape AI then reviews the code in context and reports real issues with remediation.
Use it for: your own repositories or client code you are contracted to audit — never for private code you are not authorized to review.
Where: New scan → Website. Requires the I am authorized to scan this website checkbox.
From one seed URL Vulnscape:
accept= gaps.With deep active tests enabled (default):
Retry-After, RateLimit-* headers and common WAF throttle cues. HIGH when none is observed under the burst (a DDoS or abuse spike can keep being served and inflate hosting bills); INFO when limiting is confirmed. This is not the New scan “Rate limit requests” checkbox, which only paces Vulnscape’s own outbound traffic.Long website scans run in the background. The scan detail page polls until the status leaves RUNNING. Raw evidence is stored even when zero findings are produced.
Where: New scan → Secrets.
Paste a public share URL — Claude Code / ChatGPT share pages, GitHub gists, Pastebin or any public http(s) paste. Vulnscape fetches the content (SSRF-guarded), extracts text and hunts for accidentally leaked credentials so owners can be warned to rotate.
What it detects:
Live-validate (optional, read-only):when checked, Vulnscape calls each provider's documented read-only endpoint (e.g. OpenAI GET /v1/models, GitHub rate-limit, Stripe balance) to see if the key still authenticates. Active keys are CRITICAL. Validation never mutates provider state and never moves crypto funds. Cap: 15 checks per scan.
Redaction: raw secrets are masked (sk-ant-…wxyz style) before storage, before Vulnscape AI sees the evidence, and in reports. Use this to warn owners — Vulnscape does not auto-notify third parties.
Where: New scan → Dependencies.
Paste or upload package.json, a lockfile, or requirements.txt. Pinned versions are matched against the OSV.dev vulnerability database. Each CVE is explained with an upgrade path.
Where: New scan → Passwords.
Enter up to 20 passwords (one per line). Each is scored locally for length, entropy, character classes, keyboard sequences and common-password lists, then checked against Have I Been Pwned using k-anonymity (only a SHA-1 hash prefix is sent). Raw passwords are never stored, and Vulnscape AI receives metrics only.
Where: New scan → Network. Requires authorization.
Probes common TCP ports, resolves DNS, evaluates SPF/DMARC email posture and performs deep TLS certificate inspection — including Heartbleed on port 443 when applicable. SSRF-guarded: localhost, private and link-local ranges are refused.
Where: New scan → AI/GPU Infra. Requires authorization.
Fingerprints a host for exposed, unauthenticated AI/ML services and control planes — common on GPU boxes and pods — and reports each as a severity-ranked finding: Ray dashboards (CVE-2023-48022 “ShadowRay” → RCE), Jupyter, Ollama, ComfyUI, vLLM/TGI, Triton, MLflow, TensorBoard, Gradio, unauthenticated Redis, and open Docker Engine / Kubernetes / kubelet APIs.
Every check is a non-destructive, read-only fingerprint — it confirms a service is present and unauthenticated via a version/health endpoint, and never submits a job, invokes a model or reads data. SSRF-guarded and authorization-gated, like the Network scanner; pass a custom port list under advanced options or use the AI-infra default set.
Available on New scan for any scan that hits a remote target (Website, Network, AI/GPU Infra, Secrets):
Name: Value per line (e.g. Authorization: Bearer … for authenticated scans). Applied to the crawler, probes, auth check, Nuclei and SQLMap.You can also tick Add to monitored targetswhen creating most scan types (not Password) — see Monitoring & alerts below.
Vulnscape AIis Vulnscape's analysis engine (Claude). It converts scanner evidence into structured findings — title, severity (CRITICAL → INFO), category, description, evidence snippet, remediation and references — and computes a consistent risk score from severities.
Open any scan from Scans or the Dashboard. While the status is queued or running, the page polls automatically. When done you get:
Compare diffs findings and risk against a prior (or chosen sibling) scan on the same target — useful after remediation or a re-scan.
From scan detail, create a password-protected share link at /share/[token]. Recipients unlock it with the password you send them. Links can expire and be revoked. Shared pages are not indexed. Use this for client deliverables without giving console access.
Where: /app/leads.
Pipeline for inbound requests and outbound prospects. Statuses: New → Contacted → Qualified → Won / Lost. Add leads manually or capture them from a scan's contact panel.
Find leadspulls companies actively hiring engineers from public job APIs (HN Who's Hiring, Remotive, RemoteOK, Arbeitnow, The Muse, Jobicy, optionally Adzuna). With “Qualify with Vulnscape AI” ticked, Claude drops recruiters/staffing agencies, writes a one-line rationale and may infer a website (marked unverified when guessed). Results de-duplicate against your CRM. It runs only when you click the button. We do not scrape sites that forbid it (e.g. Indeed / LinkedIn).
/app/targets is your asset inventory — name, type, reference, latest risk, scan count and monitoring controls. Re-scan or delete from here. New scans create a target automatically when you supply a name.
Turn monitoring on for a target (at creation or from Targets). Nothing runs on a schedule: click Check for new alerts on the Alerts page to re-scan every monitored target, or Re-scan now on a single target. Re-scans run in the background — deep website scans can take several minutes each — and the Alerts page shows progress.
Each re-scan is diffed against the previous completed scan. New findings, risk increases and failed re-scans raise alerts in /app/alerts (unread badges in the sidebar) plus optional email / Slack notifications configured in Settings.
From /app/reports or any completed scan detail, export Markdown or a print-ready HTML view (browser Print → Save as PDF). Reports include the summary, risk score, severity breakdown and each finding with evidence and remediation — ready for client deliverables.
/app/team — create an organisation, invite seats via invite link, and list members. Operator accounts are typically provisioned by an admin with a plan assignment.
/app/integrations shows configuration status for Resend (email), Slack webhooks, Stripe billing and optional Sentry. OSV.dev CVE matching, Have I Been Pwned and Claude (Vulnscape AI) are always part of the core platform when keys are configured server-side.
/app/settings — view your plan, the analysis-engine status (API key, workspace, model) and the number of monitored targets; configure email and Slack notification preferences (severity floor).
169.254.169.254) are blocked. Secret-leak fetches re-check every redirect hop.Admin-only console pages:
/app/admin/users — create users, assign Ops / Agency, rename display name/username, create time-limited vouch accounts, extend expiry./app/admin/leads — inbound requests from the public audit/quote form (New / Contacted / Closed).