PentX
Passive recon through active testing — every finding ships with full request/response bytes, reflection offsets, a cURL repro, and OAST callbacks for blind classes.
Capabilities
$npm install -g @vaultocean/pentx
$pentx scan target.com
$pentx report --format json
$
Contribute · earn fathoms
Open issues are labelled good-first-issue. Merge a pull request and earn +100ƒ — it lands directly on your Depth profile.
Evidence-grade output
Every finding ships with full request/response bytes and a cURL repro you can paste directly into a report.
SSRF-safe
Internal IP ranges are blocked at the resolver level — it won't turn into a tool against your own infrastructure.
CI-friendly
JSON output, exit codes per severity, and a GitHub Actions workflow in the repo.
Live scanner — try it now