Frequently Asked Questions

Everything you need to know about ZScanner

General

ZScanner is a desktop web application vulnerability scanner from ZHOST Consulting Private Limited. It installs on Windows, macOS or Linux and tests web applications for over 200 vulnerability types across 19 scan modules, including SQL injection, cross site scripting, SSRF, XXE and SSTI. The scan engine runs on your own machine rather than in a vendor cloud.

ZScanner is a desktop application. There is no cloud component in the scan path: the scanner binds only to localhost on your machine, attack traffic originates from your own network, and scan results are written to your own disk. The portal receives scan count metadata for licence tracking only, never vulnerability details, report content or page data.

ZScanner runs on Windows 10 and 11 (x64), macOS on both Intel and Apple Silicon, and 64 bit Linux. One licence activates the scanner on all three platforms. Windows is the primary supported platform and ships as both an installer and a portable executable.

Yes. Because the scanner runs locally it can reach any application your machine can reach, including staging environments, applications behind a corporate VPN, and hosts on an internal network. Cloud based scanners cannot test these without exposing the application or installing a network agent.

Yes. Licences are Ed25519 signed and verified offline using a public key bundled in the application, so no network call is needed to start a scan. ZScanner periodically checks the portal to confirm the licence has not been revoked and keeps working for a bounded grace period when it cannot reach it, which makes it usable on air gapped machines.

Detection and scanning

ZScanner detects SQL injection using error based, boolean blind and time blind techniques; reflected and DOM based cross site scripting; local file inclusion; OS command injection; server side request forgery; XML external entity injection; server side template injection; CRLF injection; open redirects; business logic and authorisation flaws; weak TLS configuration and certificate problems; missing security headers; CORS misconfiguration; CSRF; insecure cookie flags; exposed backup files and secrets; and directory listings. REST and GraphQL APIs are tested as first class targets.

Yes. You record a login sequence once and ZScanner replays it, then reuses the authenticated session while crawling. It checks session health during the scan and re authenticates automatically if the session is dropped, so testing continues past the point where an unauthenticated scanner stops.

Every finding carries a confidence score and band. Each also ships a sanitised replayable request, so you can re issue the exact request that produced the finding and confirm it yourself. Suppressing a finding requires a reason, an owner and an expiry date, and the finding returns to review automatically when the expiry passes, so suppressions do not silently become permanent.

A quick scan typically finishes in minutes. A full scan usually takes 30 minutes to 3 hours, depending on how many pages the crawler finds, the crawl depth you set, how quickly the target responds, and the request delay you configure to avoid overwhelming it.

Yes. Findings are mapped to OWASP Top 10 (Web 2021), OWASP API Security Top 10 (2023) and PCI-DSS 4.0, and each report shows per framework coverage as a percentage. Reports are produced as standalone HTML and as PDF, in English, French, Spanish, Portuguese and German.

Yes. Each finding includes a replayable proof package. Re issuing it marks the finding either reproduced or candidate fixed, so verifying a patch is a single action rather than a full rescan.

Licensing and pricing

After purchase you receive a licence key by email. Open ZScanner, go to the License section, paste the key and click Activate. The key is an Ed25519 signed token verified against a public key bundled in the application, so activation needs no configuration and works offline.

Plans are priced by licence duration rather than by target, and run from one month to twelve months. Every plan includes unlimited scans, unlimited targets and all 19 scan modules. Current prices in US dollars and Indian rupees are listed on the pricing page.

No. ZScanner does not meter scans, domains, IP addresses or applications. A licence covers as many targets as you are authorised to test for the duration of the term. This differs from most commercial scanners, which are priced per application or per seat.

A licence is intended for a single user or team. For multi seat or consultancy licensing, contact sales@bithost.in.

Scanning is disabled until the licence is renewed. Reports already generated remain on your disk, and scan history held in the portal is retained.

Data handling and payments

After a scan, ZScanner sends a hash of your licence key rather than the key itself, scan timestamps, the target domain, and finding counts by severity. It does not send report content, vulnerability details, request or response bodies, or page data. Reports are uploaded to the portal vault only for licensed users and only when you choose to use that feature.

Payments are processed by Razorpay, which is PCI-DSS Level 1 compliant. Accepted methods include UPI (GPay, PhonePe, Paytm, BHIM), all major Indian debit and credit cards, Net Banking, and international Visa, Mastercard and American Express. Card and UPI details are handled entirely by Razorpay and are never stored by ZHOST.

No. The packaged application bundles its own Python runtime and every dependency. Download, install and run. There is no interpreter to install, no Docker image to pull and no build step.

Only scan systems you own or have written authorisation to test. Active scanning sends real attack traffic, which can trigger intrusion detection, fill logs, and in some configurations change application state. Unauthorised security testing is a criminal offence in most jurisdictions. ZScanner includes policy based target scope validation so an out of scope host can be blocked before a scan starts.

Still have a question?

We usually reply within a few hours on business days.

Email Support