New here? Start with an interactive guide
Step-by-step walkthroughs for the web scanner, CLI, GitHub Action, and API — written so a non-technical founder can follow along without a security background.
How does the scanner actually work?
Regex + AST dual-layer architecture, the taint tracker's source/sink coverage, the labeled fixture corpus, and the methodology used for fair comparison against Semgrep and Bearer. All open source, all reproducible locally.
Quick Start
XploitScan can be used five ways:
Paste code at xploitscan.com/scan, or sign in (free) to drag-and-drop files or paste a GitHub URL. Signed-in web scans include AI review of findings (free: 5/day).
Run npx xploitscan@1.17.0 scan . in your terminal
One-click install for automatic PR security checks. Setup guide
Auto-scan every PR with SARIF output
Scan from Claude Desktop, Cursor, or Windsurf as you code. Setup guide
CLI Usage
No account required. Install nothing — just run with npx. Without an account or ANTHROPIC_API_KEY, your code never leaves your machine; signing in sends findings (with short code excerpts) to your dashboard, and setting ANTHROPIC_API_KEY sends code to Anthropic.
$ npx xploitscan@1.17.0 scan .Scan the current directory$ npx xploitscan@1.17.0 scan ./srcScan a specific folder$ npx xploitscan@1.17.0 scan . --format jsonOutput results as JSON$ npx xploitscan@1.17.0 scan . --format sarifOutput SARIF for GitHub Security tab$ npx xploitscan@1.17.0 scan . --diff mainScan only files changed vs a base branch$ npx xploitscan@1.17.0 scan . --watchRe-scan automatically on file changesOutput Formats
terminal — Human-readable terminal output (default)json — Machine-readable JSON with all findingssarif — SARIF for GitHub Security tab integrationsplunk-hec / elastic-ecs / datadog-logs — SIEM-ready event formatsExit Codes (for CI gating)
0 — Scan completed; no critical or high-severity findings1 — Critical or high-severity findings present (fails the CI step), or the scan was blocked by your plan's rate limitMedium/low/info findings never fail the build — gate on what's exploitable, fix the rest at your own pace.
Connect Your Account (unlock all 223 rules)
Anonymous CLI scans use the 30 free rules. Logging in connects your plan — paid plans scan with all 223 rules, and your scans appear in your dashboard.
$ npx xploitscan@1.17.0 auth loginOpens your browser, links the CLI to your account — no key copying$ npx xploitscan@1.17.0 auth whoamiCheck which account and plan the CLI is using$ npx xploitscan@1.17.0 auth logoutDisconnect this machineCI & GitHub Action: use an API key
Headless environments can't open a browser. API keys are a paid-plan feature (Indie or Pro) — generate one under Settings → API Keys and provide it as api-key (GitHub Action) or the XPLOITSCAN_API_KEY environment variable. Keys are shown once and stored hashed — treat them like passwords. The MCP server and the VS Code extension run the 30 free rules with no key; to run all 223, set XPLOITSCAN_API_KEY in your MCP client's config, or run XploitScan: Enter API Key from the VS Code command palette. Both still scan locally; the key only downloads the Pro rules.
After your first logged-in scan: results land in your dashboard with history and trends, and you can publish a Trust Page to show customers your security posture.
Pre-commit Hook
Scan your code automatically before every git commit. Catches security issues before they land in your repo.
$ npx xploitscan@1.17.0 hook installInstall the hook in your git repo$ npx xploitscan@1.17.0 hook uninstallRemove the hookHow it works
xploitscan scan . --diff HEAD on every commitgit commit --no-verifyGitHub Action
Automatically scan every push and pull request. Findings appear in the GitHub Security tab (on private repos, that tab requires GitHub Code Security).
name: Security Scan
on: [push, pull_request]
permissions:
contents: read
security-events: write
pull-requests: write
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run XploitScan
uses: bgage72590/xploitscan-action@v1
with:
path: '.'
fail-on: 'critical'
comment: 'true'@v1 tracks the latest v1 release. Pin the action to a full commit SHA so a moved tag cannot change what runs: uses: bgage72590/xploitscan-action@<full-sha> # v1.6.0.
Action Inputs
path — Directory to scan (default: .)fail-on — critical: fail on critical only; high: fail on high or critical; medium: fail on medium, high, or critical; low: fail on any graded finding (critical, high, medium, or low). Info findings never fail the build. none: never fail (default: none)sarif-file — Path for SARIF output (default: xploitscan-results.sarif)comment — Post a severity-table summary comment on pull requests (default: true)api-key — XploitScan API key (xpls_...). API keys are a paid-plan feature (Indie or Pro); paid plans scan with all 223 rules, otherwise the 30 free rules runfail-on-quality — Also fail the action on high-severity code-quality findings (QA…). Off by default: quality findings are reported either way, and the exit code is a contract with pipelines that were passing before they existed. See https://xploitscan.com/quality (default: false)grade-vendored — Count findings in vendored, generated, and documentation files (components/ui, __generated__, *.md) toward the grade and the failure threshold. Off by default — those findings are reported and uploaded to the Security tab either way. Set to true if you treat vendored code as yours to maintain. NOTE: this input is what the action grades by; scan.gradeVendored in .xploitscanrc does not apply here, because the action recomputes the grade from the scan JSON rather than using the CLI's. (default: false)anthropic-api-key — Optional; enables AI analysis and the AI false-positive filter on CI runs (sends source files to Anthropic under your key)Security Badge
Add a security grade badge to your README. Configure your badge in Settings.
[](https://xploitscan.com)<a href="https://xploitscan.com"><img src="https://xploitscan-api.vercel.app/api/badge/A" alt="XploitScan"></a>Configuration
Add a .xploitscanrc file to your project root to customize scan behavior. All settings are optional: rules.disable skips rules by ID across the whole project, and ai set to false turns off the AI analysis pass (same as --no-ai). The AI false-positive review still runs whenever ANTHROPIC_API_KEY is set; unset it to keep all code on your machine.
{
"rules": {
"disable": ["VC042", "VC017"]
},
"ai": false
}SBOM Generation
Generate a Software Bill of Materials in CycloneDX 1.4 format. SBOMs catalog all dependencies and their versions for supply chain security.
Generate SBOM on the results.package.json, requirements.txt, go.mod, Gemfile, Cargo.toml, and more) are cataloged and downloaded as sbom-cyclonedx.json.Compliance Mapping
Rules carry a reference mapping to these frameworks where one applies (not every rule maps to every framework). The mapping is informational, not an audit or certification.
Trust Service Criteria mappings
Annex A control mappings
Web application risk coverage
Common Weakness Enumeration IDs
API Reference
The public scan API is available at xploitscan-api.vercel.app. No API key is required — anonymous requests run the 30 free rules under per-IP rate limits. Anonymous API results are not AI-filtered. See the API guide for a full walkthrough with request and response examples.
POST /api/scans/upload-json— Scan a JSON payload of files (4.5 MB per request (Vercel serverless request-body limit), up to 500 files); returns grade, score, and findingsPOST /api/scans/upload— Scan a ZIP upload (multipart form)GET /api/badge/:grade— Security badge image (public)Supported Languages & Files
Languages
Vulnerability rules focus on JavaScript and TypeScript (including React, Next.js, Vue and Svelte) and Python, with some rules for Ruby, Go, Java and PHP. Hardcoded-secret detection also runs on the other source files the scanner reads, such as Rust, Swift, Kotlin, C#, Dart and C/C++.
Config & IaC
Dockerfile, docker-compose, Terraform, Kubernetes manifests, GitHub Actions workflows, .env files, package.json, and more. For missing-auth checks the scanner also recognises endpoint shapes directly: Next.js App Router routes and server actions, Express and Hono route registrations, Supabase Edge Functions, Vercel serverless functions, and Netlify functions.
Need Help?
Questions or feedback? We're here to help.
Contact Us