VScanX

Open-source, offline-first Python vulnerability fuzzer

Visit Website
May 29, 2026 Launching VScanX: An open-source, offline-first security scanner built to eliminate false positives

Hi everyone,

I wanted to share VScanX, a project I have been developing over the past few months.

VScanX is a lightweight, open-source vulnerability scanner built entirely in Python, paired with a local Next.js documentation dashboard.

I started working on this tool because I was frustrated with the friction of modern security tools. Most scanners are either locked behind heavy SaaS clouds—which presents massive data privacy issues for proprietary code—or require bloated platform-specific tensor compilations just to run a quick port sweep.

I wanted to build a tool that was fast, lightweight, and could run 100% offline on a local machine. Here are the core architectural decisions behind VScanX:

1. Lazy-Loading Architecture:

To keep the basic CLI extremely lean, heavy optional dependencies like onnxruntime and Web3 libraries are lazy-loaded at runtime only if the user explicitly triggers those specific advanced modules.

2. Safe Exploit Verification:

Instead of relying on basic regex string matching that flags hundreds of false positives, VScanX verifies findings by automatically generating safe, reproducible proof-of-concept sequences to confirm exploitability.

3. Local-First Next.js Dashboard:

Rather than sending your security logs to the cloud, VScanX dumps structured JSON and runs alongside a local Next.js dashboard that renders your reports offline.

We are live on Product Hunt today to gather feedback from the developer and maker community. I would love to hear your thoughts on the architecture, or what tools you currently run in your local build pipelines.

GitHub repository: https://github.com/hnikhil-dev/VScanX

Product Hunt launch: https://www.producthunt.com/products/vscanx

Thanks for checking it out!

Comment

About

To stop alert fatigue. I built VScanX to be a fast, completely offline Python scanner that verifies vulnerabilities with safe, local exploits instead of relying on noisy false positives.