AI tools like Cursor, Lovable, Bolt, Copilot and ChatGPT make it easy to ship a website, app, CRM or codebase without a seasoned developer — and easy to ship the mistakes they leave behind. Vulnscape scans what you built and finds the vulnerabilities and errors, big or small, then explains the fix in plain English.
Why it matters
The same shortcuts that make AI-assisted building quick are the ones that get systems breached. These are the mistakes we see most often in AI-generated projects — and every one of them is something Vulnscape checks for.
SQL queries built from strings, API keys pasted into source, missing auth checks on routes, weak crypto. It runs fine in the demo — until someone pokes at it.
Missing security headers, insecure cookies, open admin logins, no rate limiting, exposed ports and debug endpoints. Boilerplate ships with the gaps included.
Dependencies with known CVEs, secrets left in shared AI chats and gists, reused passwords, expiring certificates. Small mistakes that turn into big incidents.
What we check
Point Vulnscape at your website, your code, your dependency list, your passwords, your server or your AI/GPU stack. Each scanner collects hard evidence; Vulnscape AI turns it into findings ranked by severity, with the fix.
Static review of source for SQL injection, XSS, hard-coded secrets, weak crypto and insecure patterns — a deterministic pre-pass feeds Vulnscape AI.
From one URL: same-origin crawl, security headers, cookies, TLS, forms and upload gaps — plus authorized XSS/SQLi probes, Nuclei, SQLMap, default-admin and HTTP rate-limit checks.
Parse package.json, lockfiles or requirements.txt and match pinned versions against the OSV.dev vulnerability database.
Strength and entropy scoring plus Have I Been Pwned k-anonymity breach checks. Raw passwords never leave the scan — Vulnscape AI only sees metrics.
TCP port probes, DNS records, SPF/DMARC email posture and deep TLS certificate inspection — SSRF-guarded and authorization-gated.
Find exposed, unauthenticated AI/ML services on your servers and GPU pods — Ray dashboards (ShadowRay), Jupyter, Ollama, ComfyUI, vLLM, Triton and MLflow, plus open Docker/Kubernetes APIs. Non-destructive checks, authorization-gated.
Paste a public share link — an AI chat transcript, GitHub gist or paste — and Vulnscape finds leaked API keys, private keys and wallets. Optional read-only validation shows which keys are still live.
How it works
Paste your code, a URL, a dependency file, a host or a shared link. Confirm you are authorized, then run the scan — deep website scans run in the background.
Vulnscape AI turns raw scanner evidence into findings ranked by severity — what it is, why it matters, how to fix it — plus a 0–100 risk score.
Mark targets as monitored and re-scan them whenever you ship. New issues become alerts; export or share password-protected reports with clients or stakeholders.
Mark targets as monitored, then click “Check for new alerts” whenever you want them re-scanned. New findings, risk increases and failed scans surface as alerts, with optional email and Slack notifications. Nothing runs in the background, so usage stays predictable.
Pull companies that are actively hiring engineers from seven public job boards, let Claude qualify each one as a security prospect, and file them straight into your Leads CRM — one click, whenever you need pipeline.
See it in action
Choose a scanner, point it at what you built, and get a prioritized report with plain-English remediation — plus an assistant you can ask follow-up questions, grounded in your findings.


Vulnscape AI
Scanners gather headers, ports, CVEs, password metrics, injection probes and code signals. Vulnscape AI explains what each one means for your system, scores the risk, and writes the fix — often something you can paste straight back into your AI coding tool. Ask follow-up questions in the console. Included in every plan.
Sign in to try itVulnscape AI — powered by Claude
Every scan's evidence becomes severity-scored findings with copy-paste remediation — not raw scanner noise.
Ask Vulnscape AI
Chat about a single scan or your whole portfolio: what to fix first, how to remediate, what a risk score means.
Alerts on change
Re-scan monitored targets on demand. New findings, risk increases and failed scans land in Alerts, with optional email and Slack notifications.
Pricing
Ops is for teams checking their own AI-built systems. Agency is for studios and freelancers who ship for clients — it adds the Leads CRM, on-demand lead finder and team seats.
Vulnscape Ops
For teams shipping AI-built websites, apps and code: every scanner, plain-English findings and fixes from Vulnscape AI, re-scans and alerts.
Vulnscape Agency
For studios and freelancers building with AI for clients: run client scans, find prospects on demand, and track outreach.
Online checkout is not enabled yet — contact us to subscribe. Sign in
Get in touch
Launched something with AI and want a human to look it over before customers do? Tell us what you built — website, app, CRM, integration or codebase — and we’ll come back with scope and pricing for a hands-on review. Prefer self-serve? Subscribe in the pricing section above.
FAQ
Yes, that is exactly who Vulnscape is for. AI tools are great at producing working software and poor at reviewing it. Vulnscape checks the website, code, dependencies and server you ended up with for the security mistakes an inexperienced developer would miss, and tells you how to fix them.
No. You paste a URL, upload code or a dependency file, and read the report. Vulnscape AI explains every finding in plain English with a concrete fix — usually something you can hand straight back to your AI coding tool or your developer.
Both. Findings range from critical (SQL injection, leaked API keys, default admin logins) down to informational (a missing header, a version banner, a weak cookie flag). Everything is ranked so you know what to fix first.
All six scanners (code, website, dependencies, passwords, network, secret leaks), Vulnscape AI powered by Claude, on-demand re-scans of monitored targets, alerts, reports, share links and the AI assistant.
Everything in Ops plus a Leads CRM for inbound requests and outbound prospects, an on-demand lead finder that pulls companies hiring engineers from public job boards and qualifies them with Claude, and team seats. Built for agencies and freelancers selling security work.
No. Scans, re-scans and lead searches only run when you start them. Mark a target as monitored and click “Check for new alerts” whenever you want it re-scanned — you stay in control of usage.
Yes. Use the audit / quote form on this page with your name, email, phone and company. We’ll follow up with scope and pricing.
Enter your email on the pricing section, complete Stripe Checkout, and Vulnscape creates your account automatically. A temporary password is emailed to you — then sign in at /login. Use “Forgot password” anytime to reset.
Yes. Website and network scans require an explicit authorization confirmation, and localhost / private IP ranges are blocked. Only scan systems you own or have written permission to assess.
Passwords are checked locally for strength and via HIBP’s k-anonymity API (hash prefix only). Vulnscape AI receives structural metrics — never the raw secret.
Ops: $299/month or $2,999/year. Agency: $1,299/month or $12,999/year. Same features within each plan either way.
Run your first scan in minutes. Vulnscape Ops is $299/mo or $2,999/yr.