Covers the real vuln classes
SQL injection, XSS, SSRF, IDOR/broken access control, hardcoded secrets, deserialization and weak crypto — in one pass.
Most vulnerability scanners probe your surface. Nurbak reads the source: it scans your repository with an AI model and finds exploitable vulnerabilities, secrets and misconfigurations. Free for public repos.
SQL injection, XSS, SSRF, IDOR/broken access control, hardcoded secrets, deserialization and weak crypto — in one pass.
Not a wall of CVSS scores: the risks are ordered by whether an attacker could actually reach and chain them.
Paste a repo URL and go — no agent, no CI setup required to get your first result.
Runs on our own model on throwaway infra; your code isn't sent to a third-party AI and is deleted after the scan.
Enter a public repository as owner/repo.
We run our Whitehat model on ephemeral infrastructure.
The scanner reads and correlates code across files.
You get a ranked vulnerability score in minutes.
Unlock the full report and private-repo scans on a plan.
A code (SAST-style) vulnerability scanner powered by an AI model. It reads your source code and finds exploitable vulnerabilities, rather than only probing a running app from the outside.
Yes for public GitHub repositories. Private repositories and the full report with file, line and fix are available on paid plans.
Injection (SQLi, command), XSS, SSRF, broken access control/IDOR, exposed secrets, insecure deserialization, path traversal and weak cryptography, among others.
Yes. Analysis runs on ephemeral infrastructure with our own model, your code is never sent to OpenAI or Anthropic, and it is deleted when the scan finishes.
Get a ranked, exploitability-first vulnerability score in minutes.
Scan my repo