LIGHTWEIGHT · SELF-HOSTED · PHP 8
Recon, without
the fog.
VulnX scans a single domain you own — XSS, SQLi, open redirects, exposed files and weak headers — with a live console and PDF reports. No subdomain enumeration. No daemons. Just cron + PHP.
Built for precision,
designed for shared hosting.
Live scanning console
Watch progress, HTTP requests and findings stream in real time as each module runs — pause, resume or stop without losing state.
Single-target focus
Only the domain you provide is scanned. No accidental scope creep, no subdomain storms.
Context-aware payloads
XSS payloads tailored to the reflection context; SQLi across four detection techniques.
Pause. Resume. Stop.
Full control over every scan. State persists in the database.
JSON + PDF reports
Raw JSON or a clean, branded PDF with findings and PoC snippets.
Zero dependencies
Pure PHP 8 + cURL + PDO. One cron entry on cPanel.
Three phases. One queue.
START SCANNING
Run your first scan in under a minute.
Pick a target you own, choose your phases, and watch evidence stream in live. No credit card, no setup beyond one cron line.
WELCOME BACK
Log in
Resume your scans and reports.
New here?
JOIN VULNX
Create account
Start scanning in under a minute.
Have an account?
DASHBOARD
Welcome back.
NEW SCAN