Skip to content

Scanning Guide

RejectModders edited this page Aug 24, 2026 · 2 revisions

Scanning Guide

VulnRadar has several scan modes, all documented and runnable in the app:

  • Quick scan: a single URL. Start at https://vulnradar.dev
  • Deep (crawl) scan: same-origin crawl of multiple pages.
  • Authenticated scan: scan behind a login (form, header, cookie, or a rendered SPA login). Credentials are used in memory only and never stored.
  • Bulk scan: up to 100 URLs at once.
  • Active probing (opt-in): submits real payloads through discovered forms to confirm SQL injection, reflected XSS, SSTI, OS command injection, and open redirects. Domain-ownership-gated and off by default.

Results are deterministic (same URL produces the same finding IDs), so two scans can be diffed against each other. Full how-to and options: https://vulnradar.dev/docs

Clone this wiki locally