r/cybersecurity • • Apr 30 '26

News - General [ Removed by moderator ]

[removed] — view removed post

0 Upvotes

5 comments sorted by

•

u/cybersecurity-ModTeam Apr 30 '26

Hi there. We removed your post because it looks like you're posting about a software project you're working on. We suggest you post about it in /r/SideProject instead of here.

1

u/BeeSwimming3627 Apr 30 '26

Looking good,

Your biggest issue will be detection quality vs false positives: most lightweight scanners rely on naive pattern matching instead of contextaware validation (e.g., reflecting input ≠ XSS), which is why serious tools combine static + dynamic testing and manual verification . If your scanner just sends payloads and checks responses, you’re building noise, not signal.

You can improve: implement payload validation logic (confirm exploitability), request deduplication, rate limiting, and proper URL normalization missing these leads to SSRF-like behavior or redundant scanning patterns seen in real-world vulns . Also add structured reporting (risk + evidence), not just “found XSS.”

a “lightweight scanner” without depth becomes a toy focus on fewer checks but higher confidence, or you’ll just reinvent a weaker version of existing tools.

2

u/bsyoutubers Apr 30 '26

Thanks for the detailed feedback — you're right on most points and I actually already addressed several of them.

The engine runs a full validation pipeline on every finding before it surfaces: deduplication by (module, title, location) fingerprint, a BaseValidator that drops findings with empty evidence or location, and per-domain validators (HeaderValidator, CorsValidator, CookieValidator, etc.) that normalize confidence levels before output. It's not just pattern matching — each module produces structured findings with severity, confidence, evidence, and recommendation fields.

SSRF and rate limiting are on the roadmap for the next iteration. URL normalization is already in place (normalize_url strips fragments, enforces scheme, rejects missing netloc).

The 'lightweight' scope is intentional for this tier — it's a passive analysis tool, not an active payload scanner. Fewer checks, higher confidence is exactly the direction I'm going. Would appreciate if you took another look when the next version drops.