# Vuln0x — Security Intelligence Platform > AI-powered security intelligence platform for vibe-coded projects. Find vulnerabilities in your Replit, Bolt, Lovable, Cursor, and v0 apps with 40+ parallel scanner engines and Sentinel — an autonomous AI penetration testing agent. Built by Solustiq Yazilim ve Yapay Zeka Teknolojileri A.S. Website: https://vuln0x.com --- ## Features ### Security Scanners 40+ parallel scanning engines covering: HTTP security headers (HSTS, CSP, X-Frame-Options, Permissions-Policy), SSL/TLS certificates and configuration, CORS policy analysis, cookie security flags, directory and file exposure (.env, .git, backups), DNS security (SPF, DMARC, DNSSEC), open port detection, technology fingerprinting, SQL injection, XSS, command injection, path traversal, SSTI, SSRF, XXE, and more. ### Sentinel — AI Penetration Testing Agent Sentinel is an autonomous AI agent that conducts penetration tests using natural language commands. Powered by 29+ Kali Linux tools including nmap, nuclei, sqlmap, nikto, gobuster, ffuf, whatweb, testssl, subfinder, wafw00f, wpscan, and more. It follows a 7-phase attack methodology: 1. **Recon & Fingerprinting** — WAF detection, DNS enumeration, technology fingerprinting, subdomain discovery, port scanning 2. **Surface Analysis** — Vulnerability templates, web server scanning, directory brute-forcing, SSL/TLS analysis 3. **CMS-Specific** — WordPress (wpscan), Joomla (joomscan), Drupal (droopescan) targeted scanning 4. **Parameter & JS Analysis** — Parameter discovery, JavaScript endpoint extraction, secret detection 5. **Active Vulnerability Testing** — SQL injection, command injection, XSS testing with specialized tools 6. **Auth & Session** — JWT analysis, OAuth testing, credential security, session management 7. **Infrastructure** — Cloud configuration, container security, infrastructure assessment Sentinel is available on Professional ($79/mo) and Business ($199/mo) plans. It costs 2 credits per message and 1 credit per tool execution. ### Next.js & React Security Dedicated scanners for framework-specific vulnerabilities: source map exposure, client-side secret leakage in JavaScript bundles, authentication logic flaws, cross-site scripting (XSS), server-side request forgery (SSRF), and other issues that generic scanners miss. ### Active Vulnerability Scanners Advanced active testing scanners: SQL injection (error-based, blind, union-based), XSS (reflected, DOM-based, stored), command injection, path traversal, SSTI, SSRF, XXE, CSRF, credential security, session analysis, JWT, OAuth, IDOR, privilege escalation, GraphQL security, file upload, and business logic testing. ### Risk Scoring Every scan produces a 0-100 security score with a letter grade (A+ to F). Scores are broken down by category so you can see exactly where your application is strong or weak. ### Scheduled Scans Automate security monitoring with daily, weekly, biweekly, or monthly scans. Receive HMAC-signed webhook notifications when new vulnerabilities are found or your security score changes. ### Reports & Compliance Export in six formats: SARIF (GitHub Security tab integration), CSV (spreadsheet analysis), PDF (professional reports with executive summary), HTML (shareable web reports), Markdown (documentation), and JSON (structured data for CI/CD pipelines). ### Projects & Profiles Group multiple URLs into projects. Create scan profiles to customize which engines run. Track security posture across your entire portfolio. ### API & CI/CD REST API with Bearer token and API key authentication. Trigger scans from GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, or any CI/CD system. SARIF reports integrate directly with GitHub Security tab. ### AI Remediation Assistant AI-powered chat interface that provides contextual remediation guidance for findings. Get actionable fix suggestions, executive summaries, and security advice for every vulnerability. --- ## Pricing ### Free - 50 credits included - All 40+ scanner engines - No credit card required - Price: $0 ### Starter - 300 credits per month - Everything in Free - Scheduled scans (3) - 2 concurrent scans - Scan sharing - 1-month credit rollover - Price: $29/month ($24/month annual) ### Professional - 1,000 credits per month - Everything in Starter - Sentinel AI agent (50 messages/mo) - All report formats (PDF, SARIF, HTML, MD) - AI remediation (50/mo) - 5 concurrent scans - 15 scheduled scans - Scan comparison - Jira & GitHub export - Slack & Discord integrations - Full API access - 2-month credit rollover - Price: $79/month ($66/month annual) ### Business - 3,000 credits per month - Everything in Professional - Sentinel AI agent (200 messages/mo) - 10 concurrent scans - Unlimited scheduled scans - AI remediation (200/mo) - All integrations (Slack, Discord, Teams) - Custom security badge - 3-month credit rollover - Dedicated support - Price: $199/month ($166/month annual) ### Credit Costs - Full scan: 10 credits - Full deep scan: 20 credits - Individual scanner: 1-10 credits (depends on complexity) - Supabase security scan: 15 credits - Full advanced scan: 120 credits - Sentinel message: 2 credits - Sentinel tool execution: 1 credit --- ## Frequently Asked Questions ### What is Vuln0x? Vuln0x is an AI-powered security scanning platform designed specifically for web applications built with AI-assisted coding tools like Replit, Bolt, Lovable, Cursor, and v0. It runs 40+ parallel scanner engines to detect vulnerabilities in headers, SSL/TLS, CORS, cookies, directories, DNS, ports, and more — including framework-specific scanners for Next.js and React. ### What is Sentinel? Sentinel is Vuln0x's autonomous AI penetration testing agent. You describe what you want to test in natural language, and Sentinel plans and executes a multi-phase penetration test using 29+ Kali Linux tools. It chains findings together — discovering a subdomain leads to scanning it, finding WordPress leads to running wpscan, detecting a WAF leads to adapting its strategy. Available on Professional and Business plans. ### What types of vulnerabilities can it detect? Our 40+ scanners detect missing security headers (HSTS, CSP, X-Frame-Options), SSL/TLS certificate issues, CORS misconfigurations, insecure cookies, exposed files and directories (.env, .git, backups), DNS misconfigurations (SPF, DMARC, DNSSEC), open ports, technology fingerprinting, source map exposure, client-side secret leakage, SQL injection, XSS, command injection, path traversal, SSTI, SSRF, XXE, CSRF, IDOR, privilege escalation, JWT/OAuth flaws, and more. ### Does it support Next.js and React-specific issues? Yes. We have dedicated scanners specifically designed for Next.js and React applications. These detect source map exposure, client-side secrets leaked in JavaScript bundles, authentication logic flaws, cross-site scripting (XSS), server-side request forgery (SSRF), and other framework-specific vulnerabilities that generic scanners miss. ### How does credit-based pricing work? Every new account receives 200 free credits. A full scan costs 10 credits and a full deep scan costs 20 credits. Individual scanner types cost 1-10 credits each depending on complexity. You can purchase additional credits or upgrade to a plan with monthly credit allocations starting at 300 credits/month. ### Can I integrate it into my CI/CD pipeline? Absolutely. Our REST API supports both Bearer token and API key authentication. You can trigger scans from GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, or any CI/CD system. SARIF reports integrate directly with GitHub Security tab, and JSON reports are optimized for automated pipelines. ### What report formats are available? We support six export formats: SARIF (for GitHub Security tab integration), CSV (for spreadsheet analysis), PDF (professional reports with executive summary), HTML (shareable web reports), Markdown (for documentation), and JSON (structured data for CI/CD pipelines and custom integrations). ### Is my data safe during scanning? We only perform non-invasive scanning — we never attempt to exploit vulnerabilities, modify your application, or store sensitive data. All scan results are encrypted at rest and in transit. You can delete your scan history at any time. We are committed to responsible security testing practices. ### What are scheduled scans? Scheduled scans let you automate security monitoring. Set up daily, weekly, biweekly, or monthly scans for any verified domain. You will receive webhook notifications and optional email alerts when new vulnerabilities are found or your security score changes. ### Can I scan multiple URLs at once? Yes. You can use our Projects feature to group multiple domains together and scan them all with a single command. You can also use the bulk scan API endpoint to submit multiple URLs simultaneously. Each URL is scanned independently and results are tracked per target. ### Do I need to verify my domain before scanning? Yes. Vuln0x requires domain verification to ensure you have authorization to scan a target. You can verify ownership via DNS TXT record or HTML file upload. This prevents unauthorized scanning and ensures responsible use of the platform. ### Do you offer a free tier? Yes. Every new account receives 50 free credits — enough for 5 full scans or 50 individual scanner runs. No credit card is required to sign up. ### What is the difference between passive and active scanning? Passive scanners analyze publicly visible information like HTTP headers, SSL certificates, DNS records, and exposed files without sending attack payloads. Active scanners test for exploitable vulnerabilities like SQL injection, XSS, and command injection by sending carefully crafted test payloads. Both types are available on Vuln0x. --- ## Pages ### Product - Home: https://vuln0x.com - Features: https://vuln0x.com/features - Security Scanners: https://vuln0x.com/features/security-scanners - Risk Scoring: https://vuln0x.com/features/risk-scoring - Next.js & React Security: https://vuln0x.com/features/nextjs-react-security - Scheduled Scans: https://vuln0x.com/features/scheduled-scans - Reports & Compliance: https://vuln0x.com/features/reports-compliance - Projects & Profiles: https://vuln0x.com/features/projects-profiles - API & CI/CD: https://vuln0x.com/features/api-cicd - Sentinel AI Agent: https://vuln0x.com/features/sentinel - Pricing: https://vuln0x.com/pricing ### Resources - Documentation: https://vuln0x.com/docs - API Reference: https://vuln0x.com/docs/api - Blog: https://vuln0x.com/blog - Changelog: https://vuln0x.com/changelog - System Status: https://vuln0x.com/status ### Company - About: https://vuln0x.com/about - Careers: https://vuln0x.com/careers - Brand: https://vuln0x.com/brand ### Legal - Terms of Service: https://vuln0x.com/legal/terms - Privacy Policy: https://vuln0x.com/legal/privacy - Security Policy: https://vuln0x.com/legal/security - Acceptable Use Policy: https://vuln0x.com/legal/aup - Service Level Agreement: https://vuln0x.com/legal/sla - Data Processing Agreement: https://vuln0x.com/legal/dpa - Authorization Policy: https://vuln0x.com/legal/authorization ### Social - Twitter/X: https://x.com/vuln0x - GitHub: https://github.com/vuln0x - LinkedIn: https://linkedin.com/company/solustiq