Detection library
Our own rule library, written and maintained in-house, is what lets a scan say “this specific version of this specific stack, misconfigured in this specific way” instead of “port 443 is open”.
- Severity distribution
- 1,974 Critical · 2,026 High · 3,276 Medium · 1,437 Low · 1,333 Informational. The weighting is deliberate: most real-world risk sits in the middle band, where misconfiguration lives.
- What the rules look for
- 5,950 misconfiguration checks, 1,402 default-credential and default-configuration checks, 1,385 hardening-baseline checks and 1,232 end-of-life / unsupported-version checks.
- Coverage by stack
- Packs for PHP, Java, .NET, Node, Python, Go, Ruby, Rust, Kotlin, Swift, Dart, Elixir, Scala and more — plus web servers, CMS platforms, and front-end and back-end frameworks.
- Written, not scraped
- Rules are authored and reviewed by our team against vendor advisories and lifecycle data. Every pack carries a version and a review date.