SmartScanner

AI-guided web scanner for fast, no-setup security checks and CI-ready automation
Rating
Your vote:
No screenshots
Used by 1 person
Notify me upon availability

Open your project dashboard, paste a URL, and press Scan. That’s the entire setup. SmartScanner immediately explores the site the way a user would, learning forms, routes, and states as it goes. You can narrow scope with include and exclude rules, set a crawl depth, or keep defaults for a quick sweep. Provide login details or a session cookie to test member-only paths; the scanner walks through sign-in screens and preserves sessions automatically. Single-page apps are handled with a headless browser, so dynamic content, API calls, and client-side routing are covered. As results arrive, you see a live inventory of pages, parameters, and services, with issues sorted by severity and risk so you know where to act first.

For day-to-day development, drop SmartScanner into your CI. Use the CLI or container to hit preview or staging URLs on every pull request. Configure a policy to fail builds on high or critical findings, and let moderate issues pass with warnings. Baseline mode compares new runs to previous ones so you catch regressions without noise. Tag scans by microservice or repository and schedule nightly sweeps for broader coverage. Short on time? Run a fast check that targets changed paths only; before a release, run a deeper pass that exercises forms, file uploads, and authenticated flows. All activity and outcomes are recorded for audit and compliance.

Fixing issues is straightforward. Each finding includes the exact request and response, reproduction steps, and a replay button for validation in a safe sandbox. The scanner also identifies the framework and server stack in use and tailors guidance accordingly, offering framework-specific fixes and sample patches where possible. Mute known false positives, set due dates, and push tickets to Jira, Azure Boards, or GitHub with one click. After a patch, run Retest to verify the fix in isolation and close the loop. Export machine-readable results (JSON or SARIF) for tooling, or generate clean PDFs for stakeholders with executive summaries and technical detail.

Advanced controls let you scan responsibly in any environment. Throttle request rates, honor 429s, and respect allowlists and blocklists to avoid disruption. Add custom headers, route traffic through a proxy, or use client certificates for hardened backends. SmartScanner probes for common web risks including injection flaws, cross-site scripting, SSRF, path traversal, auth and session weaknesses, misconfigurations, and secret exposure. It also checks policy gaps like missing security headers, weak cookie flags, and permissive CORS. Use the API to orchestrate scans across many apps, apply consistent policies, and stream results to your SIEM. Whether you are validating a bug bounty report, prepping for a penetration test, or protecting a fast-moving release train, SmartScanner fits cleanly into your workflow and keeps findings actionable.

Review summary

Features

  • One-click scan with no setup required
  • Behavior-aware crawling for SPAs and dynamic routes
  • Authenticated scanning via credentials or session cookies
  • Tech stack detection with framework-specific guidance
  • CLI and container for CI integration
  • Policies to break builds on high-severity issues
  • Baseline diffs to catch regressions
  • Incremental and full-depth scan modes
  • Live findings with replayable proofs
  • False positive suppression and retest
  • Exports in JSON, SARIF, and PDF
  • Role-based access and audit logging
  • Rate limiting, allowlists, and blocklists
  • Custom headers, proxies, and client certs
  • REST API for automation

How It’s Used

  • Run quick pre-merge security checks on preview environments
  • Schedule nightly scans across all services and compare drift
  • Scan authenticated areas of an admin portal before go-live
  • Validate and close bug bounty submissions with replayable POCs
  • Generate executive and technical reports for audits
  • Retest patches to confirm vulnerabilities are resolved
  • Gate releases by failing builds on critical findings
  • Automate multi-app coverage via API in a central pipeline

Plans & Pricing

Free

Free

Unlimited Targets
Unlimited Scans
On-premises Installation
Limited Functionality*

Pro

$20.00 per month

Unlimited Targets
Unlimited Scans
On-premises Installation
Full Functionality
Regular Updates
Priority Support

Perpetual

$599.00 per Seat

Unlimited Targets
Unlimited Scans
On-premises Installation
Full Functionality
1 Year Free Updates
1 Year Priority Support
Offline Scans

Comments

User

Your vote: