VAPT Insights

Website Security & Vulnerability Scanning

Visit Website
August 1, 2026 I built a free security scanner suite — zero traffic, zero leads. What am I doing wrong?

Hey IH 👋

I'm a developer who built VAPT Insights — a set of free security

scanning tools for web applications.

What it does:

• Security Headers Scanner — check any website for CSP, HSTS,

X-Frame-Options, etc.

• SSL/TLS Analyzer — detect weak ciphers, expired certs, deprecated

protocols

• Open Port Scanner — find exposed database ports, admin consoles

• SBOM Viewer — free CycloneDX dependency tree visualizer

• DPDP Compliance Scanner — India's new data protection law

(think GDPR for India)

No signup required for any of these. Completely free.

I also built a GitHub Action that plugs into CI/CD pipelines —

generates SBOMs on every deploy and alerts on Slack/Discord when

new CVEs hit your dependencies.

Stack: Next.js (frontend), Go/Fiber (backend), PostgreSQL

The problem: I've been heads-down building for months. 12 blog posts

written. Tools are working. But traffic is basically zero. No signups.

No leads.

I know I have a distribution problem, not a product problem. I've

started posting on LinkedIn this week and submitted to a few

directories, but I'd love to hear from founders who've been in

this spot:

1. What worked for you to get your first 100 users?

2. For dev tools specifically — where did your early traffic come from?

3. Am I missing something obvious?

Site: https://www.vaptinsights.com

Free scanner: https://www.vaptinsights.com/security-headers

Roast it, break it, tell me what sucks. Honest feedback > polite

encouragement.

Comment

May 1, 2025 What is VAPT Insights?

VAPT Insights is a comprehensive security auditing platform designed to identify vulnerabilities, misconfigurations, and missing protections in your web applications. Perform instant scans to stay ahead of cyber threats and improve your site's security.

Comment

About

VAPT Insights is a comprehensive security auditing platform designed to identify vulnerabilities, misconfigurations, and missing protections in your web applications. Perform instant scans to stay ahead of cyber threats