nowfound

Alternatives

Products that do what XploitScan does

Security scanner built for AI-generated code

  1. 1
    Gammacode269

    Web and Terminal agents that scan, fix, and ship secure code

    Oct 2025

  2. 2

    An open source security scanner for Visual Studio Code

    2020

  3. 3AA

    Hi, I’m Kenny, I’ve been building aislop. I starting working on this after using Claude Code, codex and opencode several times and noticing some slops. They aren’t syntax and passes most tests, they are patterns like empty catch blocks, useless comments, duplicated helpers, dead code and many more. So I built a tool to scan and check for these patterns and wired it into hooks so after each tool call, the agent checks for the slops. You can try it out with npx aislop scan. It’s all local and no code is transferred. Thank you.

    May 2026 · github.com

  4. 4

    Scan any LLM chatbot for vulnerabilities

    Apr 2026 · github.com

  5. 5FL

    Hi HN! We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated. We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40%…

    2025

  6. 6VD

    Did you know that VSCode extensions run with full access to your system—including file system, network, and credentials? Worse, dozens of malicious extensions have already made it into the marketplace, silently compromising devices. I am a security researcher and student developer who ran into this problem myself. To help tackle this, I built a 100% free tool (no login required) that scans VSCode (and Cursor/Windsurf) extensions for: - Hidden malware and obfuscated code - Dangerous permissions and API misuse - Vulnerable dependencies and suspicious network connections Users have already…

    2025 · vscan.dev

  7. 7

    Security Scanner for AI-generated Code

    8d ago · scanity.dev

  8. 8AC

    Hey HN, I’m Henry, cofounder and CTO at Span (https://span.app/). Today we’re launching AI Code Detector, an AI code detection tool you can try in your browser. The explosion of AI generated code has created some weird problems for engineering orgs. Tools like Cursor and Copilot are used by virtually every org on the planet – but each codegen tool has its own idiosyncratic way of reporting usage. Some don’t report usage at all. Our view is that token spend will start competing with payroll spend as AI becomes more deeply ingrained in how we build software, so understanding how…

    Sep 2025 · code-detector.ai

  9. 9BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  10. 10
    Trestle54

    Stop AI-written code from leaking secrets

    Jun 2026 · trestlescan.com

  11. 11

    AI security scanner that finds & fixes bugs before they ship

    26d ago · devaiopshub.com

  12. 12

    Scan AI-generated code: 48 bug patterns, 9 languages

    Jun 2026 · pleasing-transformation-production-90c2.up.railway.app

  13. 13KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com

  14. 14

    Find security bugs in AI-generated code before hackers do

    May 2026 · codecop.io

  15. 15

    Scan your code for vulnerabilities

    Apr 2026 · cyber-security-code-scan.base44.app

  16. 16

    Local security & compliance scanner for AI agents

    Jul 2026 · safeclaude.net

  17. 17

    Open-source malware scanner and runtime guard for AI agents

    Jul 2026 · panguard.ai

  18. 18IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  19. 19

    Catch code vulnerabilities before they ship.

    Jul 2026 · vuln-shield.vercel.app

  20. 20TO

    I'm an infrastructure architect who started using AI assistants to write code 3 months ago. After building several systems with Claude, I noticed a pattern: the code always had security issues I could spot from my ops background, but I couldn't fix them myself since I can't actually write code. Why I built this: I needed a way to verify AI-generated code was production-safe. Existing tools either required cloud uploads (privacy concern) or produced output too large for AI context windows. TheAuditor solves both problems - it runs completely offline and chunks findings into 65KB segments that…

    Sep 2025 · github.com

  21. 21

    Python security scanner that eliminates false positives

    Feb 2026

  22. 22
    VScanX11

    Deterministic security scanner with zero false positives

    May 2026 · vscanx.vercel.app

  23. 23
    vett5

    Scan, sign, and verify AI agent skills before installing

    Feb 2026

  24. 24

    Autonomous AI Agent Scanner for Web Security & UI Issues

    Feb 2026

Ranked by how close each launch is in meaning, then by votes. Refine with a description →