Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

September 2026

June 2026

  1. AI where it earns its place in the Website Scanner and URL Fuzzer

    Copy link to “AI where it earns its place in the Website Scanner and URL Fuzzer”

    We added AI to the Website Scanner and URL Fuzzer in the exact spots where deterministic logic used to give up. Three enhancements shipped:

    • AI-assisted authentication: when authentication fails to identify a login form the usual way, an AI fallback steps in to find it, so complex login flows stop cutting scans short.

    • Flowmapper: an AI agent explores your site like a real user, filling forms and following flows to reach endpoints the regular spider misses, then adds them to the scan.

    • ML Classifier: filters out fake “not found” pages that return a 200 status, so the admin console, sensitive file, and information disclosure checks report real findings instead of error pages in disguise. The URL Fuzzer runs the same classifier, so its results list only the files and directories that actually exist.

    Why it matters

    Fewer false positives and fewer missed endpoints, without manual tuning. The AI handles the judgment calls that used to break scans or bury real findings in noise.

    How to use

    Everything is on by default. You can disable any or all of it under My account, then AI.

    See it live

April 2026

  1. Private key detection in Website Scanner

    Copy link to “Private key detection in Website Scanner”

    The Website Scanner now detects private keys exposed in HTTP responses. The check runs passively - no configuration required, no extra setup.

    RSA, EC, and other common formats are included. If a private key is leaking from your target, this surfaces it. An attacker with that key has full access to whatever server infrastructure it belongs to. These findings get missed in manual testing because the response looks like noise until you look closely.

    Useful for external pentests and internal security reviews of web application infrastructure.

    Run a web scan

March 2026

  1. AI-enhanced authentication inside the Website Scanner

    Copy link to “AI-enhanced authentication inside the Website Scanner”

    The Website Scanner's Automatic and Recorded authentication methods now use AI as a fallback when standard login detection fails. On complex or dynamic pages, the AI layer kicks in and completes the login reliably. It only intervenes when the current method can't.

    What's in it for you:

    • Fewer failed scans on modern web apps with non-standard login flows

    • No configuration changes needed

    • More consistent scan coverage across authenticated areas of your targets

February 2026

  1. Deeper visibility into findings, directly in scan logs

    Copy link to “Deeper visibility into findings, directly in scan logs”

    The Website Scanner and API Scanner already display findings while the scan runs. Scan logs now also record the exact moment when a new finding is added directly in the console output.

    This provides a more granular, step-by-step view of discovery as the scan progresses.

    Scan log new finding

    Why this matters:

    • See the precise moment a vulnerability is identified during longer scans

    • Correlate findings with specific scan phases or payloads

    • Troubleshoot unexpected behavior with additional context

    • Gain better traceability in API-driven or automated workflows

    For teams running continuous or automated testing, this adds clearer operational insight during the scan itself, not only after it finishes.

January 2026

  1. Surface more request smuggling issues with fewer false positives

    Copy link to “Surface more request smuggling issues with fewer false positives”

    We’ve improved the detection accuracy of active detectors in the Website Vulnerability Scanner to surface more real issues with less noise.

    This update adds coverage for:
    • CSRF bypass via POST/PUT to GET conversion
    • Insecure CORS configurations caused by subdomain trust
    • Serialized object detection in JSON payloads to flag potential deserialization risks

    These improvements help reduce false positives and provide clearer signals during validation and triage.

November 2025

  1. SQLi detectors uses more payloads in all custom cookies and has reduced false positives

    Copy link to “SQLi detectors uses more payloads in all custom cookies and has reduced false positives”

    We’ve just rolled out an update to Website Scanner’s active SQLi detection: it now injects payloads into all custom, non-standard cookies and cuts down false positives by skipping cookies that were already checked. This means broader coverage on real-world apps that stash input in quirky cookie names, without noisy duplicates in your results.

    Why it matters
    SQL injection still shows up in places scanners can miss, especially in custom cookies used for state, feature flags, or tracking. By extending payload injection to every custom cookie, Website Scanner can uncover SQLi paths that previously hid outside “standard” cookie patterns. At the same time, the improved logic avoids re-testing cookies it has already validated, which reduces repeat hits and lowers the chance of false positives. Net effect: more real findings, less triage fatigue.

    How to use

    Run Website Scanner as usual → review any confirmed SQLi findings → validate further with SQLi Exploiter if needed → fix and re-scan to confirm remediation and ensure no custom-cookie vectors remain exposed.

  2. Added CL.0 request smuggling detection in our HTTP desync attacks active detector

    Copy link to “Added CL.0 request smuggling detection in our HTTP desync attacks active detector”

    Inspired by James Kettle's article and to keep on top on latest research, we introduced the new CL.0 Request Smuggler in our HTTP Request Smuggling detector from Website Vulnerability Scanner. It is automatically enabled inside the detector and it helps uncover more request smuggling attacks.

August 2025

  1. Take control of web app auth check and findings

    Copy link to “Take control of web app auth check and findings”

    Fresh improvements to our proprietary Website Scanner let you handle authentication and findings with less hassle and more clarity:

    Record auth flows with Chrome – We’ve moved to Chrome Developer Tools to record and configure logins faster and with more reliability. Start here.

    Re-enabled Check Authentication  – Test your credentials upfront and see a screenshot of a successful login, so you know it works.

    Spot outdated server software clearly – The scanner creates a separate finding for each vulnerable technology instead of lumping them together, so you can act on what matters.

    Product interface jquery findings image

  2. Prioritize more accurately with EPSS scoring

    Copy link to “Prioritize more accurately with EPSS scoring”

    We’ve expanded support for the Exploit Prediction Scoring System (EPSS) to help you quickly assess which vulnerabilities are most likely to be exploited:

    For the Website Scanner – Findings now show the CVE name and EPSS score right at the top, so you immediately know which ones attackers are most likely to exploit.

    For the WordPress & Drupal Scanners – Findings now include EPSS data and are better organized with CVE name, score, and percentile highlighted.

    WP-seopress plugin findings image

July 2025

  1. The Website Scanner’s spidering process now uses Locality Sensitive Hashing (LSH) to compare similar pages more efficiently.

    What this means for you:

    ✅ Cover more ground in less time and surface hidden endpoints quickly

    ✅ Improve test coverage on apps with repetitive structures or dynamic content

    You may see more URLs discovered in your scans - slightly longer scan time, but way better visibility!

    We’re constantly optimizing our proprietary Website Scanner for better scan performance.

June 2025

  1. Cut through the noise with ML-powered false positive filtering

    Copy link to “Cut through the noise with ML-powered false positive filtering”

    False positives don’t just waste time - they erode trust, delay remediation, and bury real issues under a pile of noise.

    That’s why we’ve built and integrated the Machine Learning classifier - a purpose-trained machine learning model - directly into our Website Scanner and URL Fuzzer.

    Instead of relying on brittle RegEx logic, the ML Classifier analyzes every HTML response during a scan and automatically sorts it into one of four smart categories:

    📌 HIT – High-value targets like login pages, exposed secrets, and backups

    📌 MISS – Confirmed dead ends, even when status codes are misleading

    📌 PARTIAL HIT – Ambiguous but interesting results (like firewall pages or redirects)

    📌 INCONCLUSIVE – Requires browser-based rendering for confirmation

    This means you can quickly focus on what matters, reduce triage time, and get clearer, cleaner results.

May 2025

  1. Deeper findings with Website Scanner upgrades

    Copy link to “Deeper findings with Website Scanner upgrades”

    We’ve made several key improvements to our proprietary Website Scanner to help you uncover more vulnerabilities - with greater precision:

    ✅ Light scans now include all passive detections so you get richer results with a quick scan
    ✅ GraphQL endpoint fuzzing now included to automatically identify GraphQL endpoints and test them as injection points
    ✅ Response Header Injection detection is still live in the active module since last month, but too useful not to mention again!

March 2025

  1. Catch email leaks, DOM-based redirects & XSS with ease

    Copy link to “Catch email leaks, DOM-based redirects & XSS with ease”

    This month’s Website Scanner updates help you uncover hard-to-spot web app issues faster:

    📌 Redirects buried in JavaScript can slip past traditional scans. Now our scanner checks for DOM-based open redirects, giving you deeper visibility into vulnerable behavior inside the browser.

    📌 See emails as standalone findings for faster review and better reporting.

    📌 Found an XSS? No need to manually recreate your payload - just click “Exploit with XSS Exploiter” in the Website Scanner and capture screenshots, cookies, and request data every time it gets triggered.

February 2025

  1. Zero in on critical web app flaws – lightning fast

    Copy link to “Zero in on critical web app flaws – lightning fast”

    To help you get eyes on the most burning security issues as fast as possible, we’ve updated the Website Scanner and the API Scanner to classify the most severe risks as Critical if their CVSSv3 score is over 9.0.

    This means:

    📌 More time to realistically assess business impact

    📌 More accurate risk and mitigation prioritization.

    Plus, this month comes with even more improvements in our Website Scanner:

    • You can now test authentication with headers with the Authentication functionality, before starting a new scan for a better setup configuration.

    • The Find Login Interfaces passive test now detects Basic HTTP/NTLM Authentication — helping you map authentication entry points with greater accuracy.

December 2024

  1. Turn every web app inside out with new detections

    Copy link to “Turn every web app inside out with new detections”

    Besides finding critical vulnerabilities in web apps, our proprietary Website Scanner automatically validates them to get rid of false positives.

    In the last few weeks, we’ve added even more highly accurate detections for:

    • insecure deserialization in Ruby-based applications with the scanner’s Active module.

    • Python pickle objects, together with an out of band deserialization method so you don’t get any unwanted RCEs in production.

    Wondering what else you can detect with our Website Scanner? Find all our web app detections in the Vulnerability Database by filtering after the tool’s name!

November 2024

  1. Our proprietary Website Vulnerability Scanner just got more powerful with these November updates:

    Validate with SQLi Exploiter button: Found an SQL Injection vulnerability? Validate it instantly in one click! Our SQLi Exploiter auto-fills details like HTTP methods, POST data, and test parameters.

    Insecure deserialization detection for Python-based applications in the scanner’s Active module. (‘Nough said!)

    Subdomain whitelisting for broader scan coverage. By default, we’re whitelisting "api", but you can customize your subdomain scanning under the Custom scan settings for even more control.