Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Securiscan — Standard-library Python security triage engine that scans web apps, APIs, LLMs, and mobile packages via passive header inspection, active canary probing, and offline static diagnostics. | Kitploit
Tools/GitHubGitHub/vighnesh91/securiscan
Defensive ToolsStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisAPI Security TestingWeb SecurityPenetration TestingMobile SecurityAPI SecurityAI Security
21 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
vighnesh91/securiscan

Securiscan

Standard-library Python security triage engine that scans web apps, APIs, LLMs, and mobile packages via passive header inspection, active canary probing, and offline static diagnostics.

View Repository
Share

Securiscan

Securiscan

Securiscan is a robust, lightweight, and native standard-library security triage engine built to analyze vulnerabilities across Web Applications, APIs, LLMs, and Mobile Packages completely using Python standard built-ins.

🚀 Core Execution Modes

1. Passive External Inspection (Default Safest Mode)

Performs a native read-only standard-library GET request to analyze server cookies, session configurations, and missing header matrices (CSP, HSTS, X-Frame-Options) without sending attack payloads.

python securiscan.py -w "https://example.com"

2. Explicit Active Canary Probing (Authorized Scope Only)

Fires targeted, benign payloads to evaluate input-reflection (XSS, SSTI, SQLi) and path traversal bounds. This flag will fail closed if directed at private subnets or loopbacks without an accompanying authorization flag.

# Scan a verified public asset
python securiscan.py -w "https://example.com" --active

# Scan an authorized internal lab network
python securiscan.py -w "http://10.0.1" --active --allow-private-target "10.0.1.45"

3. Static Air-Gapped Code Diagnostics

Analyzes directories, dependency files, or configuration contexts 100% offline.

python securiscan.py -w ./source_code_dir --no-fetch --pdf triage_output.pdf

📋 Finding Policy Validation States

  • POTENTIAL: Heuristic candidate matches found via static text patterns. Requires manual context inspection.
  • OBSERVED: Direct structural configuration anomalies confirmed on live headers or server objects.
  • CONFIRMED: Vulnerability reproduced actively via baseline-aware canary payload evaluation.
Download Tool