Find what's exposed. Fix what matters.
One scan surfaces real findings in seconds. No account needed — start free, or bring PatchVex into your remediation workflow when you're ready.
Only scan sites you own or are authorized to test. Reports are stored and accessible via link — see how we handle scan data on the Trust page.
How it works
Discover, understand, fix — in that order.
Discover
Run an instant scan or import your existing Nessus results. PatchVex finds what's actually exposed — leaked keys, missing headers, weak TLS, unpatched CVEs.
Understand
Every finding comes with context — severity, real-world exploitation signals (CISA KEV, FIRST EPSS), and exactly why it matters, not just a raw CVSS number.
Fix
Clear remediation guidance for every finding — no guesswork. Re-scan to confirm the fix, and export evidence for your next audit.
The report
What a PatchVex report actually looks like.
Same components, same data model as a live scan — this is an illustrative example, not a fake mockup.
Not Ready — at least one Critical issue needs attention before launch.
This scan checks for common, known issues — it is not a guarantee your application is free of security risks.
criticalSecretsExposed OpenAI API key in publicly served codeEvidence available
A string matching OpenAI's format was found in code served to anyone who loads this page. Anyone can copy it and use it to make requests billed to your account.
Impact
Anyone who views this page can copy the key and use it to make requests billed to your account - for an LLM API key, that can mean an unbounded bill run up in minutes.
Recommended fix
Rotate this key immediately in the provider dashboard (the exposed one should be treated as fully compromised), then move all calls to this API behind your own backend so the key never reaches the browser.
Technical details
// app/api/chat/route.ts - runs server-side only
const apiKey = process.env.OPENAI_API_KEY; // no NEXT_PUBLIC_ prefix
// call the provider here, return only the result to the client// .env (never committed)
OPENAI_API_KEY=sk-...
// server.js
import 'dotenv/config';
const apiKey = process.env.OPENAI_API_KEY;
// proxy the request server-side; the browser never sees this valuemediumCookiesCookie "session" missing the Secure flagEvidence available
Without Secure, this cookie can be sent over plain HTTP, exposing it to interception on the network.
Impact
Without the Secure flag, "this cookie" can be sent over a plain HTTP connection, exposing it to interception by anyone on the same network.
Recommended fix
Set the Secure flag on "this cookie" so it is only ever sent over HTTPS.
Technical details
res.cookie('this cookie', value, { secure: true, httpOnly: true, sameSite: 'lax' });cookies().set('this cookie', value, { secure: true, httpOnly: true, sameSite: 'lax' });lowHeadersMissing Content-Security-Policy header
A CSP header restricts what scripts/resources a page can load, reducing the impact of XSS.
Impact
Review this finding and confirm whether it applies to your setup.
Recommended fix
See the description above for details.
lowCookiesCookie "session" missing the SameSite attributeEvidence available
Without SameSite, this cookie may be sent on cross-site requests, which can enable CSRF attacks.
Impact
Without SameSite, "this cookie" may be attached to requests originating from other sites, which is what makes cross-site request forgery (CSRF) attacks possible.
Recommended fix
Set SameSite=Lax (or Strict, if the cookie never needs to be sent from a cross-site link) on "this cookie".
Technical details
res.cookie('this cookie', value, { sameSite: 'lax', secure: true, httpOnly: true });cookies().set('this cookie', value, { sameSite: 'lax', secure: true, httpOnly: true });Two products today
PatchVex is a security platform — not just a scanner.
Instant security checks for any web application.
Paste a URL, get a full report in seconds.
- TLS certificate & protocol version
- Security headers & CSP validation
- Exposed OpenAI, Anthropic & cloud keys
- Cookie security flags
Rank vulnerabilities by exploitation, not severity.
5,000 findings. 19 actually exploited right now. VulnPilot tells you which.
- CISA KEV + FIRST EPSS + CVSS + severity composite scoring
- SOC 2 CC7.1 & ISO 27001 evidence
- Local-only — zero cloud upload
- Nessus CSV import
Built for developers
Fits into how you already ship.
No enterprise dashboard to learn. Run a scan from the browser, or install VulnPilot and point it at your existing Nessus export — both produce the same structured findings you can act on immediately.
See the developer workflow →$ pip install vulnpilot
$ vulnpilot update-feeds
$ vulnpilot analyze scan.csvSSRF-safe scanning
Every scan target is validated against private/internal network ranges before we ever connect. Your infrastructure is never a target.
No scan data leaves your perimeter
VulnPilot runs entirely on your machine. Findings, credentials, and scan history are never transmitted to PatchVex or any third party.
Audit-ready evidence
VulnPilot tracks every exception, SLA, and remediation with a full history. One export covers an entire audit cycle.
Open source at the core
VulnPilot is MIT-licensed and auditable. No black-box scoring — see exactly how every finding is prioritized.
Ready to check your next deploy?
Free instant scan — no account, no credit card. Evaluating PatchVex for your team or org instead?