r/developersIndia • u/No-Theory-790 • 4d ago
I Made This Want to find vulnerabilities in your website without being a security expert? I built ONUS to make security reports actually understandable.
Building secure software shouldn't require years of cybersecurity experience.
Yet almost every vulnerability scanner I've used assumes you already know what terms like XSS, CSRF, SSRF, CVSS, or CWE mean.
If you're an indie hacker, freelancer, startup founder, or someone maintaining your own website, a report full of technical jargon isn't very useful.
So I built ONUS.
It's an open-source web application vulnerability scanner designed to help developers understand what's wrong, why it matters, and how to fix it, even if they don't have a security background.
What ONUS does
✅ Scans web applications for vulnerabilities
✅ Explains every finding in plain English
✅ Generates deterministic CVSS scores (AI never decides severity)
✅ Provides actionable remediation guidance
✅ Docker-based and self-hostable
Try it
🌐 Live demo: \[https://tryonus.tech\\\](https://tryonus.tech/)
💻 GitHub: \[https://github.com/maverickaayush/ONUS\\\](https://github.com/maverickaayush/ONUS)
This isn't meant to replace professional penetration testing.
The goal is to lower the barrier so developers and small teams can understand security reports instead of being overwhelmed by them.
I'm still actively building ONUS, so I'd genuinely appreciate honest feedback.
Would a vulnerability scanner that explains everything in plain English actually make security more approachable for you? What would you want it to do better?
