Documentation

223 security rules. Five ways to scan. Everything you need to integrate XploitScan into your workflow.

New here? Start with an interactive guide

Step-by-step walkthroughs for the web scanner, CLI, GitHub Action, and API — written so a non-technical founder can follow along without a security background.

Open guides →

How does the scanner actually work?

Regex + AST dual-layer architecture, the taint tracker's source/sink coverage, the labeled fixture corpus, and the methodology used for fair comparison against Semgrep and Bearer. All open source, all reproducible locally.

Read methodology →

Quick Start

XploitScan can be used five ways:

Web App

Paste code at xploitscan.com/scan, or sign in (free) to drag-and-drop files or paste a GitHub URL. Signed-in web scans include AI review of findings (free: 5/day).

CLI

Run npx xploitscan@1.17.0 scan . in your terminal

GitHub App

One-click install for automatic PR security checks. Setup guide

GitHub Action

Auto-scan every PR with SARIF output

MCP Server

Scan from Claude Desktop, Cursor, or Windsurf as you code. Setup guide

CLI Usage

No account required. Install nothing — just run with npx. Without an account or ANTHROPIC_API_KEY, your code never leaves your machine; signing in sends findings (with short code excerpts) to your dashboard, and setting ANTHROPIC_API_KEY sends code to Anthropic.

$ npx xploitscan@1.17.0 scan .Scan the current directory
$ npx xploitscan@1.17.0 scan ./srcScan a specific folder
$ npx xploitscan@1.17.0 scan . --format jsonOutput results as JSON
$ npx xploitscan@1.17.0 scan . --format sarifOutput SARIF for GitHub Security tab
$ npx xploitscan@1.17.0 scan . --diff mainScan only files changed vs a base branch
$ npx xploitscan@1.17.0 scan . --watchRe-scan automatically on file changes

Output Formats

terminal — Human-readable terminal output (default)
json — Machine-readable JSON with all findings
sarif — SARIF for GitHub Security tab integration
splunk-hec / elastic-ecs / datadog-logs — SIEM-ready event formats

Exit Codes (for CI gating)

0 — Scan completed; no critical or high-severity findings
1 — Critical or high-severity findings present (fails the CI step), or the scan was blocked by your plan's rate limit

Medium/low/info findings never fail the build — gate on what's exploitable, fix the rest at your own pace.

Connect Your Account (unlock all 223 rules)

Anonymous CLI scans use the 30 free rules. Logging in connects your plan — paid plans scan with all 223 rules, and your scans appear in your dashboard.

$ npx xploitscan@1.17.0 auth loginOpens your browser, links the CLI to your account — no key copying
$ npx xploitscan@1.17.0 auth whoamiCheck which account and plan the CLI is using
$ npx xploitscan@1.17.0 auth logoutDisconnect this machine

CI & GitHub Action: use an API key

Headless environments can't open a browser. API keys are a paid-plan feature (Indie or Pro) — generate one under Settings → API Keys and provide it as api-key (GitHub Action) or the XPLOITSCAN_API_KEY environment variable. Keys are shown once and stored hashed — treat them like passwords. The MCP server and the VS Code extension run the 30 free rules with no key; to run all 223, set XPLOITSCAN_API_KEY in your MCP client's config, or run XploitScan: Enter API Key from the VS Code command palette. Both still scan locally; the key only downloads the Pro rules.

After your first logged-in scan: results land in your dashboard with history and trends, and you can publish a Trust Page to show customers your security posture.

Pre-commit Hook

Scan your code automatically before every git commit. Catches security issues before they land in your repo.

$ npx xploitscan@1.17.0 hook installInstall the hook in your git repo
$ npx xploitscan@1.17.0 hook uninstallRemove the hook

How it works

• Runs xploitscan scan . --diff HEAD on every commit
• Only scans files that changed in the commit (fast)
• Blocks the commit if critical or high-severity issues are found
• Preserves any existing pre-commit hooks you already have
• To skip a scan for a single commit: git commit --no-verify

GitHub Action

Automatically scan every push and pull request. Findings appear in the GitHub Security tab (on private repos, that tab requires GitHub Code Security).

.github/workflows/security.yml
name: Security Scan
on: [push, pull_request]

permissions:
  contents: read
  security-events: write
  pull-requests: write

jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run XploitScan
        uses: bgage72590/xploitscan-action@v1
        with:
          path: '.'
          fail-on: 'critical'
          comment: 'true'

@v1 tracks the latest v1 release. Pin the action to a full commit SHA so a moved tag cannot change what runs: uses: bgage72590/xploitscan-action@<full-sha> # v1.6.0.

Action Inputs

path — Directory to scan (default: .)
fail-on — critical: fail on critical only; high: fail on high or critical; medium: fail on medium, high, or critical; low: fail on any graded finding (critical, high, medium, or low). Info findings never fail the build. none: never fail (default: none)
sarif-file — Path for SARIF output (default: xploitscan-results.sarif)
comment — Post a severity-table summary comment on pull requests (default: true)
api-key — XploitScan API key (xpls_...). API keys are a paid-plan feature (Indie or Pro); paid plans scan with all 223 rules, otherwise the 30 free rules run
fail-on-quality — Also fail the action on high-severity code-quality findings (QA…). Off by default: quality findings are reported either way, and the exit code is a contract with pipelines that were passing before they existed. See https://xploitscan.com/quality (default: false)
grade-vendored — Count findings in vendored, generated, and documentation files (components/ui, __generated__, *.md) toward the grade and the failure threshold. Off by default — those findings are reported and uploaded to the Security tab either way. Set to true if you treat vendored code as yours to maintain. NOTE: this input is what the action grades by; scan.gradeVendored in .xploitscanrc does not apply here, because the action recomputes the grade from the scan JSON rather than using the CLI's. (default: false)
anthropic-api-key — Optional; enables AI analysis and the AI false-positive filter on CI runs (sends source files to Anthropic under your key)

Security Badge

Add a security grade badge to your README. Configure your badge in Settings.

Markdown[![XploitScan](https://xploitscan-api.vercel.app/api/badge/A)](https://xploitscan.com)
HTML<a href="https://xploitscan.com"><img src="https://xploitscan-api.vercel.app/api/badge/A" alt="XploitScan"></a>

Configuration

Add a .xploitscanrc file to your project root to customize scan behavior. All settings are optional: rules.disable skips rules by ID across the whole project, and ai set to false turns off the AI analysis pass (same as --no-ai). The AI false-positive review still runs whenever ANTHROPIC_API_KEY is set; unset it to keep all code on your machine.

.xploitscanrc
{
  "rules": {
    "disable": ["VC042", "VC017"]
  },
  "ai": false
}

SBOM Generation

Generate a Software Bill of Materials in CycloneDX 1.4 format. SBOMs catalog all dependencies and their versions for supply chain security.

On a Pro or Team plan (or during a trial), scan your project in the web scanner, then click Generate SBOM on the results.
Dependency manifests in your upload (package.json, requirements.txt, go.mod, Gemfile, Cargo.toml, and more) are cataloged and downloaded as sbom-cyclonedx.json.

Compliance Mapping

Rules carry a reference mapping to these frameworks where one applies (not every rule maps to every framework). The mapping is informational, not an audit or certification.

SOC 2

Trust Service Criteria mappings

ISO 27001

Annex A control mappings

OWASP Top 10

Web application risk coverage

CWE

Common Weakness Enumeration IDs

API Reference

The public scan API is available at xploitscan-api.vercel.app. No API key is required — anonymous requests run the 30 free rules under per-IP rate limits. Anonymous API results are not AI-filtered. See the API guide for a full walkthrough with request and response examples.

POST /api/scans/upload-json— Scan a JSON payload of files (4.5 MB per request (Vercel serverless request-body limit), up to 500 files); returns grade, score, and findings
POST /api/scans/upload— Scan a ZIP upload (multipart form)
GET /api/badge/:grade— Security badge image (public)

Supported Languages & Files

Languages

Vulnerability rules focus on JavaScript and TypeScript (including React, Next.js, Vue and Svelte) and Python, with some rules for Ruby, Go, Java and PHP. Hardcoded-secret detection also runs on the other source files the scanner reads, such as Rust, Swift, Kotlin, C#, Dart and C/C++.

Config & IaC

Dockerfile, docker-compose, Terraform, Kubernetes manifests, GitHub Actions workflows, .env files, package.json, and more. For missing-auth checks the scanner also recognises endpoint shapes directly: Next.js App Router routes and server actions, Express and Hono route registrations, Supabase Edge Functions, Vercel serverless functions, and Netlify functions.

Need Help?

Questions or feedback? We're here to help.

Contact Us