
Standard-library Python security triage engine that scans web apps, APIs, LLMs, and mobile packages via passive header inspection, active canary probing, and offline static diagnostics.
Securiscan is a robust, lightweight, and native standard-library security triage engine built to analyze vulnerabilities across Web Applications, APIs, LLMs, and Mobile Packages completely using Python standard built-ins.
Performs a native read-only standard-library GET request to analyze server cookies, session configurations, and missing header matrices (CSP, HSTS, X-Frame-Options) without sending attack payloads.
python securiscan.py -w "https://example.com"
Fires targeted, benign payloads to evaluate input-reflection (XSS, SSTI, SQLi) and path traversal bounds. This flag will fail closed if directed at private subnets or loopbacks without an accompanying authorization flag.
# Scan a verified public asset
python securiscan.py -w "https://example.com" --active
# Scan an authorized internal lab network
python securiscan.py -w "http://10.0.1" --active --allow-private-target "10.0.1.45"
Analyzes directories, dependency files, or configuration contexts 100% offline.
python securiscan.py -w ./source_code_dir --no-fetch --pdf triage_output.pdf