Tools · Security
Find the security holes most scanners miss.
ReconX is a free, open-source tool that checks your website for security problems, the way a real attacker would try, but safely and on your side. It tests using several user accounts at once, catches mistakes other tools miss, and uses AI to double-check its own results so your team isn't chasing false alarms.
Why It's Different
Most scanners check one login. Real apps have many.
Most tools only check what happens when you're logged in as one person. But real problems often show up between users, like when one customer can accidentally see another customer's private data. ReconX tests with several accounts at once, so this kind of mistake, one of the most common security problems found in real audits, actually gets caught instead of missed.
- 27 built-in checks
- Free & open source
- Free to use commercially
- No signup, no trial
Scan Profiles
Six ways to scan, pick what fits.
Choose how deep to go, from a five-minute check to a full review.
Quick
A fast first look that catches the obvious problems before going deeper.
Standard
A balanced, everyday check. What most scans use by default.
Deep
Every check running, plus a real browser test for modern, interactive websites.
API-Only
Checks only the behind-the-scenes systems your app talks to, not the visible website.
OWASP Top 10
Covers the ten most common, most dangerous web security problems, as defined by the security industry's own standard list.
Passive
Just looks and listens, never tries to break anything. Safe to run on your live, real website.
27 Built-In Checks
Covers the industry's standard list, and more.
This is real testing, not just a checklist. Each check uses more than one method to confirm what it finds, so you can trust the result.
- Access Control
- Multi-Identity (BOLA/BFLA)
- SQL Injection
- NoSQL Injection
- XSS
- SSRF
- Command Injection
- XXE
- SSTI
- IDOR
- JWT Analysis
- CSRF
- CORS
- Clickjacking
- File Upload
- Directory Traversal
- Open Redirect
- API Security
- Security Headers
- Cookie Security
- Session Security
- SSL/TLS Analysis
- Subdomain Takeover
- Sensitive Files
- HTTP Methods
- Information Disclosure
- Email Security
- Template Checks
AI Review
AI that saves your team time, not adds to it.
The AI double-checks every result and flags anything that's probably a false alarm, so your team isn't stuck sorting through junk. If something real is found, it always stays marked as real.
Reads results in context
Every result gets reviewed for what it actually means, not just matched to a simple rule.
Flags false alarms
Results that are probably not real get flagged, so your team spends less time chasing dead ends.
Shows how issues connect
Separate problems get linked together, showing how someone could chain them into a real attack.
Tests built for your site
Test attempts are created specifically for your website, not copied from a generic list.
Reports anyone can read
Turns technical findings into a report that people outside the security team can actually understand.
Works with Claude, GPT-4, or your own private AI model, your choice.
Quick Start
Up and running in under 5 minutes.
Reports come out as HTML, PDF, Word, or JSON files. Completely free, no signup, and no trial that runs out.
Open By Default
ReconX is one of six open-source tools we build.
Smurf, SyncerD, Naoru, Vanisec, and more, all born from real client work, then open-sourced.
Explore All ToolsWork With Us
Need a real penetration test, not just a scan?
ReconX is the tool. Our team runs it, and knows what to do with what it finds.
Talk to an Expert