Alternatives
Products that do what VulScan does
Python security scanner that eliminates false positives
- 1

- 2BB
This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…
2024 · github.com
- 3VD
Did you know that VSCode extensions run with full access to your system—including file system, network, and credentials? Worse, dozens of malicious extensions have already made it into the marketplace, silently compromising devices. I am a security researcher and student developer who ran into this problem myself. To help tackle this, I built a 100% free tool (no login required) that scans VSCode (and Cursor/Windsurf) extensions for: - Hidden malware and obfuscated code - Dangerous permissions and API misuse - Vulnerable dependencies and suspicious network connections Users have already…
2025 · vscan.dev
- 4

- 5

- 6SI
Hey HN, TL;DR: We’ve launched a free version of our Shadow IT scanner to identify which SaaS apps are used in your company, who uses them, and if they have high-risk OAuth scopes. Philip and I went through YC with AccessOwl in 2022. We started the company because, in our previous roles, we struggled to track all the SaaS apps, users, and granted OAuth scopes. The Shadow IT scanner started as a small feature within AccessOwl, which manages SaaS vendors and user accounts centrally. But a standalone scanner would have made our lives so much easier in our previous roles. So, we thought, why not…
2024 · accessowl.io
- 7

- 8

- 9

- 10
- 11
- 12

Proves vulnerabilities before reporting them.
9d ago · dashboard-seven-self-13.vercel.app
- 13KD
I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…
Nov 2025 · github.com
- 14

- 15

- 16

- 17
GhostCheck ▲5Nessus gives 200 findings. We give 3 confirmed ones.
Jun 2026 · ghostcheck-landing-page.vercel.app
- 18

- 19

- 20

- 21AM
2020 · github.com
- 22
Scan any website for security issues in 10 seconds. Free.
Feb 2026 · guardscan.dev
- 23

- 24VV
Apr 2026 · vulnetix.com
Ranked by how close each launch is in meaning, then by votes. Refine with a description →