Guide · 2 min
Scan from the browser
The fastest way to run your first scan. No install and no command line. Paste code or a single file without an account; a free account adds folder/ZIP uploads and public GitHub URLs. Best for indie hackers, founders, and anyone who just wants to know if their app is hackable.
Open the scanner
Visit the scan page. Free scans run 30 rules: 3 a day without an account, 5 a day with a free account. Paid plans unlock all 223 rules; Indie includes 500 scans a month, and Pro and Team are unlimited.
Pick how you want to upload code
You have three options. Pick whichever is easiest:
📁 Upload a folder or ZIP (free account)
Sign in, then drag your project folder or a ZIP into the drop zone. The scanner will extract source files only —
node_modules,.git, build outputs are skipped automatically.📋 Paste a single file
Without an account, use the “Paste Code” or “Upload File” tab to drop in a single file. Useful for testing one specific function or webhook handler.
🐙 Paste a public GitHub URL (free account)
Sign in and paste any public GitHub repo URL. Your browser fetches the repo's source files from GitHub (up to 200) and sends them to the scanner. For private repos, use the CLI on your own machine — see theCLI guide.
Wait for the scan to finish
The scan runs against rules tuned for AI-generated code (Cursor, Bolt, Lovable, Replit patterns) — 30 on a free scan, all 223 on a paid plan.
What you should see while it runs:
- · “Extracting files...” (if you uploaded a ZIP)
- · “Scanning N files for vulnerabilities...”
- · A grade circle (A+ to F) and a list of findings
Read the findings
Findings are sorted by severity. The dashboard now also surfaces a “Top Fixes to Make Right Now” card with the three highest-severity issues for the latest scan.
🔴 Critical
Fix immediately. These are exploitable. Examples: hardcoded API keys, unprotected webhooks, SQL injection.
🟠 High
Fix before your next deploy. Examples: missing auth on admin routes, weak crypto, CORS misconfigs.
🟡 Medium
Plan to fix this sprint. Examples: insecure cookies, missing security headers.
🔵 Low
Best-practice fixes. Examples: webhook handlers without idempotency or replay protection, TODO/FIXME comments left in code.
Apply a fix and re-scan
Each finding comes with a copy-paste fix snippet. Apply it, then run the scan again. The dashboard will show how many issues you fixed compared to your previous scan.
Troubleshooting
“ZIP file too large”
Re-zip the project without
node_modules,.git,dist, and.next. The browser starts struggling above ~100MB.“No readable source files found”
Make sure you're uploading source code (.js, .ts, .py, .go, etc.), not compiled bundles or images.
“Scan failed”
Try a smaller folder first. If it still fails, paste a single file to confirm the scanner is reachable, then email admin@xploitscan.com.
Want this to run automatically on every commit?
Next: Set up the CLI →