
VScanX
Open-source, offline-first Python vulnerability fuzzer
Hi everyone,
I wanted to share VScanX, a project I have been developing over the past few months.
VScanX is a lightweight, open-source vulnerability scanner built entirely in Python, paired with a local Next.js documentation dashboard.
I started working on this tool because I was frustrated with the friction of modern security tools. Most scanners are either locked behind heavy SaaS clouds—which presents massive data privacy issues for proprietary code—or require bloated platform-specific tensor compilations just to run a quick port sweep.
I wanted to build a tool that was fast, lightweight, and could run 100% offline on a local machine. Here are the core architectural decisions behind VScanX:
1. Lazy-Loading Architecture:
To keep the basic CLI extremely lean, heavy optional dependencies like onnxruntime and Web3 libraries are lazy-loaded at runtime only if the user explicitly triggers those specific advanced modules.
2. Safe Exploit Verification:
Instead of relying on basic regex string matching that flags hundreds of false positives, VScanX verifies findings by automatically generating safe, reproducible proof-of-concept sequences to confirm exploitability.
3. Local-First Next.js Dashboard:
Rather than sending your security logs to the cloud, VScanX dumps structured JSON and runs alongside a local Next.js dashboard that renders your reports offline.
We are live on Product Hunt today to gather feedback from the developer and maker community. I would love to hear your thoughts on the architecture, or what tools you currently run in your local build pipelines.
GitHub repository: https://github.com/hnikhil-dev/VScanX
Product Hunt launch: https://www.producthunt.com/products/vscanx
Thanks for checking it out!
About
To stop alert fatigue. I built VScanX to be a fast, completely offline Python scanner that verifies vulnerabilities with safe, local exploits instead of relying on noisy false positives.

Comment