Enterprise Security Assessment Platform

Find Critical Vulnerabilities
Before Attackers Do

A professional desktop vulnerability scanner with 19 active scan modules. Runs entirely on your machine — no cloud, no agents, and no scan data leaving your network.

Signed license keys · Instant email delivery · Runs 100% offline
19
Scan Modules
40+
Vuln Classes
11
WAF Signatures
ZScanner v3.0 — Scan in progress
[CRAWL]100 pages · 17 forms · 4 JS files
[SQLI]Union-Based · /shop?search= · CRITICAL
[SQLI]Error-Based · /products?id= · CRITICAL
[XSS]Reflected XSS · /search?q= · HIGH
[INJECT]Command Injection (blind) · /export
[AUTH]No rate limiting · /login · HIGH
[SSL]Certificate expiring in 12 days · MEDIUM
[REPORT]Done · C:19 · H:44 · M:5 · Total:70
OWASP Top 10 Aligned
Fully Offline
Windows · Linux · macOS
VAPT-Ready Reports
CVE-Based Detection
No Data Leaves Your Machine

19 Modules. Enterprise Coverage.

Each module is independently tested. No generic signatures, only confirmed evidence-backed findings with remediation guidance.

SQL Injection

Error-based, union-based, Boolean-blind and time-based. Covers MySQL, PostgreSQL, MSSQL, Oracle and SQLite.

Command Injection

Direct output and time-delay blind detection. Unix sleep and Windows ping payloads. Confirmed 2/2 probes required.

Cross-Site Scripting

Reflected (HTML, script, event context), DOM-based source-to-sink analysis, stored XSS indicators.

SSTI (Template Injection)

Jinja2, Freemarker, Twig, ERB probes with echo-vs-eval verification. Server-side evaluation leads to RCE.

SSRF

AWS/GCP metadata probes, localhost bypass, protocol smuggling, DNS rebinding indicators.

LFI / Path Traversal

/etc/passwd, win.ini, PHP wrappers, encoding bypass. 23 payload variants with confirmation checks.

Authentication Flaws

Rate limiting gaps, brute-force unprotected endpoints, JWT algorithm confusion, default credentials, account enumeration.

GraphQL & API Security

Introspection enabled, IDE exposure, mass assignment, HTTP parameter pollution, unauthenticated data endpoints.

Business Logic

Forced browsing to admin paths, price/quantity manipulation, HTTP verb tampering, path normalisation bypass.

Security Headers

CSP, HSTS, X-Frame-Options, CORS misconfiguration, CSRF, cookie security flags, each with proof-of-absence.

SSL/TLS Deep Scan

Cert expiry and hostname mismatch, TLS 1.0/1.1 active test, weak ciphers (RC4/DES), mixed content.

Reconnaissance

102 sensitive paths, Spring actuators, .git/.env/.htaccess exposure, phpinfo, Swagger, admin panels.

Passive Analysis

JS secret scanning for AWS keys, API tokens, JWTs and hardcoded IPs. Zero additional requests sent.

Advanced Threats

IDOR sequential enumeration, NoSQL operator injection, host header injection, cache poisoning.

AI / LLM Security

OWASP LLM Top 10 for AI-backed apps: prompt injection, system-prompt leakage, insecure output handling and sensitive data disclosure.

Bot Defense Posture

Fingerprints WAF / bot-management / CAPTCHA (Cloudflare, Akamai, DataDome) and flags auth endpoints that lack anti-automation controls.

Sensitive File Exposure

Exposed .git/.env, config backups, database dumps, phpinfo, server-status, and directory listing. Each match is content-confirmed to avoid false positives.

Open Redirect

Unvalidated redirect parameters tested with external canaries (Location, meta-refresh, JS redirect). Maps to CWE-601 phishing and OAuth abuse.

GraphQL Deep Security

Introspection enabled, exposed GraphiQL/Playground IDE, and field-suggestion schema leakage on GraphQL endpoints.

Built for what other scanners miss

Most scanners stop at the OWASP basics and send your data to the cloud. ZScanner goes further — and stays on your machine.

Privacy by design

100% offline. Your data never leaves.

The entire scan engine runs as a local desktop app. No cloud account, no agents, no telemetry of your findings — ideal for regulated and air-gapped environments.

  • No cloud upload of targets or results
  • Works fully air-gapped
  • One signed license, unlimited scans
100%
Fully Offline
No cloud upload of targets or results
Works fully air-gapped
One signed license, unlimited scans
AI / LLM Security — OWASP LLM Top 10
Bot Defense — WAF / CAPTCHA fingerprint
GraphQL Deep Security
SSRF · SSTI · Open Redirect
Sensitive File Exposure
Next-gen coverage

AI/LLM & bot-defense testing built in

ZScanner tests the things modern apps actually ship: LLM endpoints for prompt injection and system-prompt leakage, plus WAF/bot-management posture — coverage traditional scanners simply don’t have.

  • OWASP LLM Top 10 checks
  • WAF / CAPTCHA / bot fingerprinting
  • GraphQL, SSRF, SSTI and more
Client-ready output

Professional PDF reports, in your language

Every scan produces a penetration-test-grade PDF: cover page, executive summary, CVSS and OWASP mapping, proof-of-concept and remediation — generated in English, French, Spanish, Portuguese or German.

  • Cover page + executive summary
  • CVSS scores & CWE/OWASP mapping
  • Five report languages
Cover · Executive Summary
CVSS · CWE · OWASP mapping
Proof-of-Concept · Remediation
EN · FR · ES · PT · DE

Serious coverage, measured

19
Scan modules
40+
Vulnerability classes
5
Report languages
0
Cloud dependencies

Scan in Three Steps

From install to a complete vulnerability report in under an hour.

01

Enter the Target URL

Paste the URL, choose a scan mode, configure crawl depth, set cookies or auth headers. ZScanner maps every page, form, and API endpoint automatically using its intelligent crawler.

02

19 Modules Run in Parallel

Passive analysis, SSL deep scan, recon, headers, SQL injection, XSS, SSRF, SSTI, authentication, API security, business logic, and advanced threats — all concurrent with real-time findings.

03

Download the Report

A print-ready report with cover page, risk score, executive summary, CVSS scores, OWASP classification, attack payloads, response evidence, and step-by-step remediation.

ZScanner vs. typical cloud scanners

The capabilities that matter, side by side.

CapabilityZScannerTypical cloud scanner
Runs fully offline / air-gapped
No data leaves your network
AI / LLM security testing
Bot-defense posture checks
Multi-language PDF reports
One price, unlimited scans

Simple, Transparent Pricing

One license key. Unlimited scans. All 19 modules included in every plan.

Starter
1 Month
$193
  • Unlimited scans & targets
  • All 19 scan modules
  • AI/LLM & bot-defense testing
  • Professional PDF + HTML reports
  • Reports in 5 languages
  • OWASP Top 10 + CVSS scoring
  • Authenticated & API (OpenAPI) scans
  • Compliance packs & custom policy gates
  • Scan history & report vault
  • Email support
Get Starter
Secured by Razorpay
Business
6 Months
$843
Save $315
  • Unlimited scans & targets
  • All 19 scan modules
  • AI/LLM & bot-defense testing
  • Professional PDF + HTML reports
  • Reports in 5 languages
  • OWASP Top 10 + CVSS scoring
  • Authenticated & API (OpenAPI) scans
  • Compliance packs & custom policy gates
  • Scan history & report vault
  • Priority support
Get Business
Secured by Razorpay
Enterprise
12 Months
$1,446
Save $870
  • Unlimited scans & targets
  • All 19 scan modules
  • AI/LLM & bot-defense testing
  • Professional PDF + HTML reports
  • Reports in 5 languages
  • OWASP Top 10 + CVSS scoring
  • Authenticated & API (OpenAPI) scans
  • Compliance packs & custom policy gates
  • Scan history & report vault
  • Early access to new modules
  • Dedicated support & onboarding
Get Enterprise
Secured by Razorpay

  Supports UPI · All Indian cards · Net Banking · International cards. License delivered instantly to your email.

Common Questions

ZScanner runs 19 active scan modules covering SQL injection (all techniques), XSS, command injection, SSTI (leads to RCE), SSRF, LFI, authentication flaws, GraphQL/API security, JWT issues, broken access control, SSL/TLS weaknesses, security header misconfigurations, and more — over 200 vulnerability types across the OWASP Top 10.

ZScanner is a fully offline desktop application for Windows, Linux, and macOS. Scan results stay on your machine. Only finding counts (not vulnerability details) are sent to zscanner.bithost.in for license tracking.

After payment, your license key arrives by email within seconds. Open ZScanner → Settings → License tab → Paste the key → click Activate. The app verifies the key against the portal and you're ready to scan.

ZScanner must only be used on systems you own or have explicit written permission to test. Unauthorised security testing is illegal. The tool is built for professional VAPT assessments and testing your own infrastructure.

We use Razorpay, which supports all major Indian debit/credit cards, UPI (GPay, PhonePe, Paytm, BHIM), Net Banking, and international Visa/Mastercard/Amex. INR and USD pricing available.

License purchases are final, but we stand behind the product. If ZScanner does not work as described, email support@bithost.in with your order ID and our team will help resolve it.

All plans include the same full-featured scanner with all 19 modules. The only difference is the license duration (1, 3, 6, or 12 months). Longer plans offer significant savings per month.

Still have a question?

We usually reply within a few hours on business days.

support@bithost.in

Start finding what others miss

Download ZScanner free and run your first scan today. Upgrade to a license anytime for the full 19 modules.

v3.0.0 · 109.3 MB · SHA256: 1018e5ba17cb1f8eb1ee…