Upload your project files to scan for security vulnerabilities
Paste code or upload a file — free instant scan, no signup required.
🔒 Scanned in memory and never stored by XploitScan. Signed-in scans can run AI review of findings (free accounts: 5/day; Privacy Policy §7). Prefer fully local? Signed out and without ANTHROPIC_API_KEY set, the CLI keeps your code on your machine: npx xploitscan@latest scan .
A free account adds ZIP and multi-file uploads, 5 scans per day, your scan history, and a dashboard. No credit card required.
Drop your project files or a ZIP. We extract only source code — binaries and build artifacts are automatically skipped.
Our engine runs up to 223 security rules (30 on the free tier) checking for hardcoded secrets, SQL injection, XSS, SSRF, NoSQL injection, XXE, SSTI, command injection, weak crypto, Docker/K8s security, CI/CD vulnerabilities, and more.
Get plain-English explanations and fix suggestions for every vulnerability found.