Changelog

What's new in XploitScan

6 changes

  • +The GitHub Action installs CLI 1.17.0 exactly and fails the job if that scan crashes or does not write a scan result. A normal scan still passes or fails only from the fail-on setting. Pin the action with a full commit SHA (`bgage72590/xploitscan-action@<full-sha>`) instead of a tag that can move.
  • +CLI 1.18.0 (shared rules 2.4.0): findings in test and fixture files stay in the report and do not change the grade, except a live-format provider key. Dependency advisories count as one ADVISORY family. A placeholder or templated database URL no longer flags, and a real password in a database URL still does. JSON output includes the grade and the score, and the ungraded field covers test-file holdouts.
  • +C# files named like FooTests.cs stay in the report and no longer lower the grade. A file named SpeedTest.cs, LoadTest.cs, ABTest.cs, or Models/Test.cs is still application code. A database URL is flagged only when the user and password sit on that same line. AWS access key IDs have to be the 20-character key shape, so a longer token in third-party code is not treated as a live key.
  • +Test and fixture files stay in the report and no longer lower the grade. A live provider key in a test still counts, including sk_live_ and a GitHub, Slack, or OpenAI key. A test-mode key or placeholder token does not. A real password on localhost still counts. A placeholder password does not. Documentation, schema, and timestamp URLs are not insecure HTTP. Dependency advisories count as one group. Website upload reads the same files as the command-line scanner, and scan JSON includes the grade and score.
  • +CLI 1.17.0 (shared rules 2.3.0): a scan's score now counts at most 3 findings from each rule, and every entropy hit counts as that one rule. A fourth or later finding from the same rule stays in the report and does not lower the score or the letter. Entropy also skips SBOMs and test files, so license inventories and tests no longer show up as secrets.
  • +MCP server 1.9.0 and VS Code extension 1.6.0 now grade the same way as CLI 1.17.0. A score counts at most 3 findings from each rule, and every entropy hit counts as that one rule. Entropy skips SBOMs and test files. Findings in third-party folders stay in the report and do not change the score.
16 changes

  • +The GitHub Action fail-on input now means this severity or higher: medium no longer fails a workflow on a lone low finding, and low ignores info-only findings (for example console.log). Invalid fail-on values or non-numeric counts now exit 2 instead of passing silently; an empty value still means none. This changes pass/fail for existing @v1 workflows that set fail-on to medium or low. After merge, pin @v1.5.0 or the moved @v1 tag.
  • +AI review of scan findings now runs when you are signed in — including on the homepage and demo scanners — and respects plan limits and the Settings opt-out. Signed-out scans still return the same rule findings and grade, with a one-line prompt to sign in for the AI second pass. A signed-in free user at the daily scan cap can still run a homepage demo scan; that one is deterministic, without AI. The Privacy Policy now says anonymous scans are not sent to Anthropic.
  • +Annual billing now says Save over 40%, and Team annual is $699/year on the pricing page — more than 40% cheaper than twelve monthly payments. Per-month annual rates are the yearly total divided by 12 ($58.25 Team, $9.92 Pro), not rounded to whole dollars. Annual buttons name the yearly charge; the strikethrough is twelve months of the monthly price.
  • +Paid plans now say, at Stripe Checkout and in the Terms, the price, that they renew until you cancel, and that you cancel in Settings > Billing > Manage Subscription. Team is a self-serve subscription at the price shown on our pricing page, auto-renewing like Pro. Pro and Team new subscribers get a 7-day trial (one per customer); Indie has no trial.
  • +Transactional and onboarding email now sends through Brevo. Product emails, surveys, and offers include a one-click unsubscribe. Survey answers go to Tally without your name or email.
  • +CLI 1.16.0: `xploitscan upgrade` now opens the pricing page in your browser. If the paid-plan check is briefly unavailable, the CLI keeps your last known plan for up to 7 days (the same offline grace as VS Code and MCP) instead of falling back to the free rules.
5 changes

  • +A leftover team membership on a canceled Team plan no longer unlocks Settings → API Keys. Those accounts see the same upgrade note as any other free plan. The Referral tab is now Pro and Team only (owner or admin on a team), matching the server — Indie still gets API keys, but not the referral program.
  • +Free accounts that open Settings → API Keys now see a short upgrade note and a link to pricing, instead of the key generator.
  • +A free scan now says it ran the free rule set — not the whole catalog — and shows what the rest covers, with a working upgrade button.
  • +The scan page no longer paints a full pricing box next to your daily count. Under the cap you see how many scans you have left; near it, a small upgrade button; at it, a Pro upgrade card in place of the dropzone. The free dashboard also notes that the free plan runs the free rule set.
  • +A scan on the website, the CLI, or MCP now runs the same engines and skips the same generated and demo files. Config and cross-file checks that only the CLI ran are included everywhere. Unusual files go through those checks in linear time. Paying CLI users get a download test that loads the full Pro catalogue.
2 changes

  • +Files that are large or unusually shaped — very long lines, generated code, strings that never close — now go through the SQL injection, open redirect, SSRF and regex denial-of-service checks in milliseconds, where some could take seconds. What those checks find is unchanged.
  • +Three of the new rules now catch more: JWTs decoded by hand (`JSON.parse(atob(token.split(".")[1]))`) are treated like any other unverified token, Django projects that allow every origin with credentials are flagged like FastAPI and Flask ones, and AI endpoints running as Cloudflare Workers are checked for a missing caller check.
1 change

  • +Nine new rules for the places AI-built apps leak most often: Supabase migrations that switch off row-level security or open writes to everyone, Firebase rules left open, AI and secret keys shipped to the browser, Base44 functions using the service role without checking the caller, roles read from user-editable metadata, unauthenticated AI endpoints, sessions trusted without verification, Python CORS wildcards with credentials, and prefix-only path checks. TanStack Start server functions are now checked for missing auth on the free plan.
6 changes

  • +Scanning a public GitHub repository by URL from the Scan page works again. The browser was blocking the requests to GitHub, so every GitHub URL scan stopped with "Failed to fetch".
  • +Install commands now end in `@latest` (`npx xploitscan@latest scan .`, `npx -y xploitscan-mcp@latest`). Without it, npx can keep running whichever version it cached the first time, so fixes never reach you. If your MCP config or scripts use plain `xploitscan-mcp` or `xploitscan`, add `@latest` to get current rules and fixes.
  • +A Pro or Team free trial includes everything on the plan you are trying, including all 214 rules in the CLI, GitHub Action, VS Code extension and MCP server. Free trials are limited to one per person.
  • +SQL injection detection now works in Express files that use route parameters. A route like `/users/:id` used to switch the SQL injection check off for the whole file, so a query built from `req.params` went unflagged. Update to CLI 1.12.4 or later; the web scanner and GitHub checks pick it up automatically. The homepage scanner now judges pasted code on its content. It used to label every paste as a demo file, which could lead the AI false-positive filter to dismiss real findings as example code.
  • +Fewer false alarms on static sites and browser games. Namespaced storage keys like `myapp.settings` are no longer reported as secrets. Rate-limit findings need a real server, and N+1 findings need a database call inside the loop. SRI isn't suggested for vendor scripts that update in place, like Stripe.js. The CSP fix is built from your page's own scripts, and the nosniff and clickjacking fixes name the HTTP header. `// VC###-OK` markers now work on the website, as they already did in the CLI.
  • +The VS Code extension and the MCP server now work like the CLI: 30 free rules with no account, all 214 on a paid plan. Generate an API key under Settings → API Keys on an Indie, Pro or Team plan, then run "XploitScan: Enter API Key" in VS Code, or add `XPLOITSCAN_API_KEY` to the MCP server's `env` block. Scans still run locally; your code is never uploaded. This arrives in VS Code extension 1.3.0 and MCP server 1.6.0; earlier versions still run every rule without a key.
1 change

  • +`npx xploitscan cursor install` works again. It writes XploitScan's security rules to `.cursor/rules/xploitscan-security.mdc` and `.cursorrules` so Cursor follows them while it writes code. Earlier versions of the CLI rejected the command. Update to CLI 1.12.2 or later.
5 changes

Safer team invitations and clearer trial reminders

  • +The GitHub Action and GitLab and Bitbucket pipelines now use `XPLOITSCAN_API_KEY` to run your plan's full rule set and add the run to your dashboard, once per CI job. If the key is mistyped or revoked, the log now says so instead of quietly scanning with the free rules. If your plan's scan limit is reached, the build keeps going on the free rules rather than failing.
  • +We updated our Privacy Policy and Terms of Service. They now describe how long we keep your data, what deleting your account removes, and how Free Trust Page data is handled. If you had an account before this update, you'll see a short notice about it in the app for the next 30 days, or until you dismiss it.
  • +Joining a team is now always your choice. When someone invites you, the invitation waits in Settings → Team, with Accept and Decline buttons and a note explaining what the team will be able to see if you accept. Invitations only match email addresses you've verified. Team owners will see invitees as Pending until they accept. If you invited someone before this change, use Resend on their invitation so they get the email with the link to accept.
  • +The trial-ending reminder in the dashboard now counts down in hours when a trial ends within a day and a half, the same way the reminder email does. Before, it rounded up to whole days, so a trial ending tomorrow night said "2 days".
  • +Trial reminders now say exactly what happens when a trial ends: the renewal amount, the date your card will be charged, and how to cancel beforehand if you don't want to continue. The Privacy Policy and Terms now describe data retention as it works today. Scan results, audit logs and checklists are kept while your account is active, and you can delete scans at any time, or delete your account from Settings to remove your data.
1 change

Plan changes and team seats

  • +Switching plans now updates the subscription you already have, wherever you start from — pricing, the scan screen, a feature prompt or settings. Each route ends at the same confirmation, with prorated billing. Team members deactivated when a plan lapsed can be brought back: they show as **Inactive** with a Re-invite button beside them. Removing someone from a team ends their access to shared scans and nothing else — their own scan history stays with their account.
2 changes

Plan status that stays current, and whole-folder uploads

  • +Your plan, trial dates and renewal date are now reconciled against Stripe on a schedule, instead of only when a billing event reaches us or you happen to open the app. A subscription that changed while you were away shows its real state the next time you look. Backing out of Stripe checkout also returns you to the plans now, rather than to the settings page.
  • +The web scanner now takes a whole folder — dragged in, or picked with Browse Folder. It walks subdirectories and skips `node_modules`, build output and `.git`, so a real project uploads in one step instead of a file selection. It also tells you when a drop contained nothing it can scan, rather than looking as though nothing happened.