Detection library
Our own rule library, written and maintained in-house, is what lets a scan say “this specific version of this specific stack, misconfigured in this specific way” instead of “port 443 is open”.
- Severity distribution
- 13,831 Critical · 28,318 High · 17,505 Medium · 7,546 Low · 1,082 Informational. Weighted towards the bands where real compromise starts: misconfiguration and exposed defaults, not theoretical edge cases.
- What the rules look for
- 40,656 misconfiguration checks, 7,249 default-credential and default-configuration checks, 5,856 hardening-baseline checks, 4,040 business-logic checks, 6,709 checks for the mistakes AI-generated code repeats, 2,859 deprecated-API checks, 788 version-specific vulnerability checks and 125 end-of-life and unsupported-version checks.
- Coverage by stack
- Packs for PHP, Java, .NET, Node, Python, Go, Ruby, Rust, Kotlin, Swift, Dart, Elixir, Scala and more — plus web servers, CMS platforms, and front-end and back-end frameworks.
- Written, not scraped
- Rules are authored and reviewed by our team against vendor advisories and lifecycle data. Every pack carries a version and a review date.