27 scanners · open source · free

Find what single-session
scanners can't see.

Multi-identity access-control testing, AI-validated findings, and a report your team will actually read.

27
Scanners
6
Profiles
MIT
Licensed
scan complete
2 critical found
27 Scanner Modules
5 AI Features
2 AI Providers
10 OWASP Top 10
6 Scan Profiles
4 Report Formats

Why Security Teams Choose ReconX

One tool. Full OWASP coverage. AI that actually reduces triage work instead of adding to it.

AC

Multi-Identity Access Control Testing

Capture two or more authenticated sessions and automatically detect broken object- and function-level authorization (BOLA/BFLA) that single-session scanners cannot see.

27

27 Scanner Modules

Comprehensive coverage from SQL injection to multi-tenant access control.

AI

Multi-LLM AI Engine

Supports Claude (Anthropic) and GPT-4/GPT-4o (OpenAI), plus any OpenAI-compatible endpoint including local and self-hosted models.

RP

Professional Reports

Generate HTML, PDF, DOCX, and JSON reports with executive summaries and OWASP coverage mapping.

OW

OWASP Top 10

Full coverage of every OWASP Top 10 (2021) vulnerability category.

SP

Scan Profiles

Quick, standard, deep, API-only, OWASP Top 10, and passive scan modes.

FP

AI False Positive Validation

AI review reduces noise by flagging likely false positives -- confirmed findings are never downgraded.

AP

Attack Path Analysis

AI maps how vulnerabilities chain together for maximum impact.

PL

Smart Payloads

Context-aware payload generation that adapts to the target.

OS

Open Source

MIT licensed, community-driven, and fully transparent.

27 Security Scanner Modules

SQL injection, XSS, SSRF, JWT flaws, multi-identity access control, and 22 more -- plus subdomain enumeration, port scanning, and tech fingerprinting before scanning starts. Each module runs multiple detection techniques, not just pattern matching.

AC Access Control (BOLA/BFLA) Multi-identity tenant/object isolation and privilege-escalation testing
DB SQL Injection Error-based, blind boolean, and blind time-based SQLi
XS XSS Scanner Reflected cross-site scripting via parameter injection
SR SSRF Scanner Server-side request forgery, in-band and out-of-band
CI Command Injection OS command injection, in-band and out-of-band
XE XXE Scanner XML external entity injection, in-band and out-of-band
TI SSTI Detection Server-side template injection (Jinja2, Twig, Freemarker)
NQ NoSQL Injection MongoDB operator and JavaScript injection
IO IDOR Scanner Insecure direct object references and ID enumeration
JW JWT Analysis Algorithm confusion, weak signing keys, forged tokens
CF CSRF Detection Missing tokens on state-changing forms
CO CORS Misconfig Wildcard origins and credential exposure
CJ Clickjacking Missing X-Frame-Options / frame-ancestors
FU File Upload Extension and content-type bypass detection
DT Directory Traversal Path traversal via ../ sequences in parameters
OR Open Redirect Unvalidated redirects via URL parameters
AP API Security Auth bypass, rate limiting, verbose error disclosure
HD Security Headers Missing CSP, HSTS, X-Content-Type-Options, and more
CK Cookie Security Missing Secure, HttpOnly, and SameSite flags
SS Session Security Session fixation, predictable tokens, weak invalidation
TL SSL/TLS Analysis Certificate issues, weak ciphers, protocol versions
ST Subdomain Takeover Dangling DNS records pointing to unclaimed services
SF Sensitive Files Exposed configs, backups, source code, admin panels
HM HTTP Methods Dangerous methods enabled (PUT, DELETE, TRACE)
IN Info Disclosure Server version leaks, debug info, stack traces
EM Email Security SPF, DKIM, and DMARC misconfigurations
TC Template Checks YAML-based checks for CVEs, exposures, and misconfigs

AI That Does More Than Write Summaries

Most tools slap an LLM on top of raw scanner output. ReconX uses AI at five stages: analysis, validation, attack path mapping, payload generation, and reporting.

01

Intelligent Analysis

AI analyzes raw scanner output to identify patterns humans might miss, correlating findings across modules to uncover complex vulnerability chains.

02

False Positive Validation

Machine learning models evaluate each finding against known patterns, reducing noise by up to 60% and letting you focus on real threats.

03

Attack Path Mapping

AI constructs exploitation chains showing how individual vulnerabilities combine for maximum impact, from initial access to data exfiltration.

04

Smart Payload Generation

Context-aware payload generation that adapts to the target application, bypassing WAFs and custom input validation.

05

Executive Reporting

AI-generated executive summaries translate technical findings into business impact language for stakeholder communication.

Scan Profiles

Choose the right level of depth for every engagement.

Quick

Headers, SSL, sensitive files, and email security in under a minute

6 modules

Standard

Balanced default coverage for routine testing

All 27 modules

Deep

Maximum depth with browser-based crawling for JS-heavy apps

All 27 modules

API Only

Focused on REST/GraphQL auth, injection, and CORS

8 modules

OWASP Top 10

Scoped to the OWASP Top 10 (2021) categories

13 modules

Passive

No active probing -- safe for production systems

4 modules

Start Scanning in 60 Seconds

ReconX is free, open-source, and MIT licensed. No signup, no trial period.

pip install reconx