Security Visibility & Remediation

Find what's exposed. Fix what matters.

One scan surfaces real findings in seconds. No account needed — start free, or bring PatchVex into your remediation workflow when you're ready.

No account requiredRead-only scanNo source code required

Only scan sites you own or are authorized to test. Reports are stored and accessible via link — see how we handle scan data on the Trust page.

How it works

Discover, understand, fix — in that order.

1

Discover

Run an instant scan or import your existing Nessus results. PatchVex finds what's actually exposed — leaked keys, missing headers, weak TLS, unpatched CVEs.

2

Understand

Every finding comes with context — severity, real-world exploitation signals (CISA KEV, FIRST EPSS), and exactly why it matters, not just a raw CVSS number.

3

Fix

Clear remediation guidance for every finding — no guesswork. Re-scan to confirm the fix, and export evidence for your next audit.

The report

What a PatchVex report actually looks like.

Same components, same data model as a live scan — this is an illustrative example, not a fake mockup.

Launch Readiness
62/ 100
Not Ready1 Critical · 0 High · 1 Medium · 2 Low

Not Ready — at least one Critical issue needs attention before launch.

This scan checks for common, known issues — it is not a guarantee your application is free of security risks.

criticalSecretsExposed OpenAI API key in publicly served codeEvidence available

A string matching OpenAI's format was found in code served to anyone who loads this page. Anyone can copy it and use it to make requests billed to your account.

Impact

Anyone who views this page can copy the key and use it to make requests billed to your account - for an LLM API key, that can mean an unbounded bill run up in minutes.

Recommended fix

Rotate this key immediately in the provider dashboard (the exposed one should be treated as fully compromised), then move all calls to this API behind your own backend so the key never reaches the browser.

Technical details

Next.js
// app/api/chat/route.ts - runs server-side only
const apiKey = process.env.OPENAI_API_KEY; // no NEXT_PUBLIC_ prefix
// call the provider here, return only the result to the client
Express
// .env (never committed) 
OPENAI_API_KEY=sk-...

// server.js
import 'dotenv/config';
const apiKey = process.env.OPENAI_API_KEY;
// proxy the request server-side; the browser never sees this value
mediumCookiesCookie "session" missing the Secure flagEvidence available

Without Secure, this cookie can be sent over plain HTTP, exposing it to interception on the network.

Impact

Without the Secure flag, "this cookie" can be sent over a plain HTTP connection, exposing it to interception by anyone on the same network.

Recommended fix

Set the Secure flag on "this cookie" so it is only ever sent over HTTPS.

Technical details

Express
res.cookie('this cookie', value, { secure: true, httpOnly: true, sameSite: 'lax' });
Next.js (Route Handler)
cookies().set('this cookie', value, { secure: true, httpOnly: true, sameSite: 'lax' });
lowHeadersMissing Content-Security-Policy header

A CSP header restricts what scripts/resources a page can load, reducing the impact of XSS.

Impact

Review this finding and confirm whether it applies to your setup.

Recommended fix

See the description above for details.

lowCookiesCookie "session" missing the SameSite attributeEvidence available

Without SameSite, this cookie may be sent on cross-site requests, which can enable CSRF attacks.

Impact

Without SameSite, "this cookie" may be attached to requests originating from other sites, which is what makes cross-site request forgery (CSRF) attacks possible.

Recommended fix

Set SameSite=Lax (or Strict, if the cookie never needs to be sent from a cross-site link) on "this cookie".

Technical details

Express
res.cookie('this cookie', value, { sameSite: 'lax', secure: true, httpOnly: true });
Next.js (Route Handler)
cookies().set('this cookie', value, { sameSite: 'lax', secure: true, httpOnly: true });

Two products today

PatchVex is a security platform — not just a scanner.

Web Scanner

Instant security checks for any web application.

Paste a URL, get a full report in seconds.

  • TLS certificate & protocol version
  • Security headers & CSP validation
  • Exposed OpenAI, Anthropic & cloud keys
  • Cookie security flags
Try the scanner →
example.com
✓ Scan complete
62
Needs Attention · 62/100
4 findings · 1 critical
CRITICALExposed OpenAI API key in publicly served code
MEDIUMCookie "session" missing the Secure flag
LOWMissing Content-Security-Policy header
LOWCookie "session" missing the SameSite attribute
vulnpilot
5,482Total findings
47Unique hosts
19KEV matches
ScorePriorityCVE / Finding
100.0CRITICAL NOWCVE-2021-44228Log4Shell (Apache log4j2)★ KEV
100.0CRITICAL NOWCVE-2023-34362MOVEit SQL Injection★ KEV
99.8CRITICAL NOWCVE-2020-1472Zerologon (Netlogon)★ KEV
23.4MEDIUMCVE-2023-44487HTTP/2 Rapid Reset Attack
11.5LOWN/ASSH Weak Cipher Suites
VulnPilot · Open Source · MIT

Rank vulnerabilities by exploitation, not severity.

5,000 findings. 19 actually exploited right now. VulnPilot tells you which.

  • CISA KEV + FIRST EPSS + CVSS + severity composite scoring
  • SOC 2 CC7.1 & ISO 27001 evidence
  • Local-only — zero cloud upload
  • Nessus CSV import
View on GitHub →

Built for developers

Fits into how you already ship.

No enterprise dashboard to learn. Run a scan from the browser, or install VulnPilot and point it at your existing Nessus export — both produce the same structured findings you can act on immediately.

See the developer workflow →
Terminal
$ pip install vulnpilot
$ vulnpilot update-feeds
$ vulnpilot analyze scan.csv

SSRF-safe scanning

Every scan target is validated against private/internal network ranges before we ever connect. Your infrastructure is never a target.

No scan data leaves your perimeter

VulnPilot runs entirely on your machine. Findings, credentials, and scan history are never transmitted to PatchVex or any third party.

Audit-ready evidence

VulnPilot tracks every exception, SLA, and remediation with a full history. One export covers an entire audit cycle.

Open source at the core

VulnPilot is MIT-licensed and auditable. No black-box scoring — see exactly how every finding is prioritized.

Read the full Trust & Security page →

Ready to check your next deploy?

Free instant scan — no account, no credit card. Evaluating PatchVex for your team or org instead?