Skip to main content

Features

Find, prove and fix vulnerabilities. Every feature, by product and plan.

capabilities that ship today. Free finds and fixes, with the proof behind every finding and no account. Pro maps the whole application and the live org. Vulkro Cloud runs it for a team.

Free 49 Pro 41 Cloud 21

Free

The local console. Every finding, the proof behind it and its fix, in your browser. Everything runs on this machine, for application code and for Salesforce.

Console guide

01What sets Vulkro apart

Attack paths, proof and checked fixes on your machine

Four things the catalogue below adds up to. Open one to see the evidence behind it.

Why Vulkro
  1. Vulkro joins who can reach the code, the entry point they use, the permission that allows it, the mode the code runs in and the data it touches. On Salesforce that means org configuration, permissions and code in one path, each step citing a file and line.

    Evidence Attack graph in every vulkro-sf scan since 0.18.0; live-org facts added with an org alias (Pro)

  2. Each finding is proven, unproven or not checked, with the data-flow steps behind it. The proof is never gated: Free shows the evidence for every finding, and Pro adds the whole-application map.

    Evidence Capability registry: finding proof, prove and explain are Free

  3. A proposed fix, deterministic or AI-drafted, is applied to a copy and scanned again. Only a patch that removes the finding without adding a new one is offered for you to apply.

    Evidence Verified fixes in vulkro 0.30.0; verify_fix MCP tool; editor AI fixes re-scanned before they are offered

  4. Analysis runs on your machine. One switch blocks every outbound call, vulnerability data updates from an offline file, and live-org reads use your own Salesforce CLI login, so no vendor holds a token.

    Evidence Offline flag and VULKRO_OFFLINE; offline update files for air-gapped installs

02The catalogue

Search every feature that ships today

Filter by product, plan or category, or search. Press / to jump to the search box.

Try
111 of 111

Find vulnerabilities 12

Detection across application code, Salesforce code and metadata, infrastructure files and AI tooling.

  • Application code scan

    Finds injection, broken access control, leaked secrets and unsafe configuration in JavaScript, TypeScript, Python, Go, Java, PHP, C and C++.

    One engine covers the languages most product teams ship, with the same results on a laptop and in CI.

    CoreFree
  • Authorization checks

    Decides for each route whether it is authenticated, scoped to the caller and role-checked, and reports lookups by id with no ownership check.

    Broken access control needs the route, the guard and the record together; a pattern match on one line cannot see it.

    CoreFree
  • Route inventory

    Lists every endpoint, including MCP and AI agent tools, with its handler, full path and the guards that protect it.

    You cannot secure a surface you have not listed, and this list comes from the code, not from documentation.

    CoreFree
  • Infrastructure files

    Checks Terraform, Kubernetes manifests, Helm charts and Dockerfiles in the same scan as the application code.

    Misconfiguration in deployment files is often how a code flaw becomes reachable from outside.

    CoreFree
  • Depth options

    Opt-in packs for business logic, money handling, state machines and concurrency, a deep preset, and import of private rule packs.

    Application-specific flaws and in-house rules run when you ask for them, in the same results and gate.

    CorePro
  • Salesforce code scan

    Scans Apex, LWC, Aura, Visualforce, Flows and metadata in an SFDX project, or metadata alone from a retrieved org.

    Security review starts before a change reaches an org, including in orgs built with clicks rather than code.

    SalesforceFree
  • Effective sharing and access mode

    Works out how each Apex class and method really runs, user or system mode, with or without sharing, along the call stack.

    Record exposure depends on the mode code actually runs in, which inheritance and API version change.

    SalesforceFree
  • CRUD and field-level security

    Reports queries and DML that skip object and field checks, and recognises user mode, stripped fields and your own security helpers.

    CRUD and FLS enforcement is a core Security Review requirement, and false alarms waste review cycles.

    SalesforceFree
  • Agentforce review

    Checks agent actions that take record ids from user input, act without confirmation, or pass model output into queries and DML.

    An agent action is a new entry point, and prompt injection turns it into a data exfiltration path.

    SalesforceFree
  • Custom rules

    Write, scaffold, validate and test your own rules over Apex syntax, XML metadata or text, and load them in every scan.

    Each org has its own policies, and they belong in the same scan as the built-in checks.

    SalesforceFree
  • Well-Architected anti-patterns

    Finds queries and DML in loops, hardcoded record ids, empty catch blocks and other Well-Architected anti-patterns in Apex.

    Governor-limit and reliability problems cause production failures that look like security incidents.

    SalesforcePro
  • Code findings and code health

    Connects a git repository read-only and shows code findings, anti-patterns, flows, test coverage gaps on attack paths and release readiness.

    Code risk sits next to org posture, so a path through untested Apex is visible in the same workspace.

    CloudCloud

Attack paths and reach 11

Who can reach a flaw, through which entry point, with which permission, and what it touches.

  • Reachability

    Tags each finding with whether an entry point reaches it, and can limit results or the build gate to reachable findings.

    Unreachable code is real debt but rarely urgent; reach is what separates the two.

    CoreFree
  • Attack paths

    Maps every entry point to every sensitive sink across the whole application, in the console and the editor.

    A list of findings says what is wrong; the map says which ones an attacker can actually chain.

    CorePro
  • Impact and code structure

    Scores what a finding reaches, lists every entry point that leads to it, and maps modules, calls and layering.

    Fixes that close the most exposure go first, and you see what depends on code before changing it.

    CorePro
  • Data-flow map

    Shows where outside data enters, what it passes through and where it ends up, including calls between your repositories.

    Reviewers follow personal and untrusted data end to end, even when it crosses a service boundary.

    CorePro
  • API contract and access matrix

    Generates an OpenAPI specification from the code and prints every endpoint against the login level it requires.

    An accurate contract and one access table make an outlier endpoint visible in a single read.

    CorePro
  • Exposure report

    Summarises one application's entry points by authentication state, unauthenticated reach to sensitive code and proven Critical and High findings.

    It answers what an anonymous attacker can reach, in a document you can hand to a reviewer.

    CorePro
  • Salesforce attack paths

    Joins who can reach the code, the door they use, the grant, the access mode and the data touched, with an entry-point inventory.

    A Critical finding comes with a path from a person to your data, each step citing a file and line.

    SalesforceFree
  • Paths checked against the live org

    Reads who holds each profile and permission set, connected-app token use and what Salesforce ships, and re-ranks the paths.

    A dangerous grant nobody holds is lowered and one held widely is raised, so priority matches the real org.

    SalesforcePro
  • Guest exposure report

    Per public site, shows what an unauthenticated visitor can read and run, with a verdict and fixes as Setup steps.

    Guest access settings decide what anyone on the internet can read from the org.

    SalesforcePro
  • Blast radius and org maps

    Shows where a component is used, what breaks if it changes, deployment and merge risk, and maps automations, roles and personal data.

    Deployments fail and leak through dependencies nobody remembered; this lists them before the deploy.

    SalesforcePro
  • Org attack paths

    Paths, a graph, the attack surface, entry points, an access graph and per-site guest exposure, joining configuration, permissions and code.

    The issues that form a path from an outsider to sensitive data are the ones to fix first.

    CloudCloud

Salesforce org posture 13

Read-only audits of a live org: identity, permissions, integrations, sessions, sharing and activity.

  • Permissions and least privilege

    Audits profiles, permission sets, groups and integration users for over-privilege, with per-user least-privilege recommendations.

    Over-privileged users and integrations turn one compromised login into full data access.

    SalesforcePro
  • Connected app and OAuth risk

    Rates every connected app and External Client App by scope, policy and who authorised it, and lists recommended revocations.

    A connected app holds a standing token into the org; the list is advice and nothing is revoked without you.

    SalesforcePro
  • Sessions, MFA and sharing

    Checks MFA, long-lived sessions, login anomalies, IP restrictions, session timeouts and over-broad sharing rules.

    Stolen sessions, weak login policy and wide sharing bypass every permission review.

    SalesforcePro
  • Threat detection and forensics

    Reads free event logs, login history and audit trails for activity to investigate, and captures a forensic snapshot for offline analysis.

    Suspicious exports and logins are visible in logs most orgs never read, and incident evidence disappears if not taken.

    SalesforcePro
  • Governance checks

    Checks backup configuration, Einstein Trust Layer settings, agent running users, folders open to portal users and credential rotation age.

    These are the questions an auditor asks, answered from the org rather than from memory.

    SalesforcePro
  • Health Check, packages and configuration

    Reads the Health Check score, installed packages, named credentials, domain, mail, limits, sandbox lag and trust status.

    Configuration drift and unverified packages are quiet ways for an org to fall out of policy.

    SalesforcePro
  • Recertification and trends

    Produces access recertification worksheets, limits and coverage risk reports, masking rules, and posture trends between audits.

    Periodic access reviews are a control requirement, and a generated worksheet makes them repeatable.

    SalesforcePro
  • Sandbox and production drift

    Compares two orgs' metadata and reports components that differ or exist in only one, with finding ids a CI job can gate on.

    A permission set that drifted between sandbox and production is where testing stops matching reality.

    SalesforceFree
  • Users, data and licences

    Every user and what an attacker could do as them, sensitive fields and who can read them, login IPs and licence usage.

    Access and data questions from auditors and responders get answered from one place.

    CloudCloud
  • Access review campaigns

    Least-privilege suggestions per user, review campaigns with assigned reviewers, keep, reduce or remove decisions and a CSV evidence export.

    Periodic access reviews become a tracked process with evidence, and Salesforce is never changed by the tool.

    CloudCloud
  • Apps and integrations

    Connected and External Client Apps, OAuth tokens and risk, API usage, Agentforce, credentials, remote sites, CORS, packages and single sign-on.

    Everything that connects into or out of the org is reviewed together, where token theft starts.

    CloudCloud
  • Suspicious activity

    Keeps each scan's normalised event history, runs baseline rules over it, files detections as issues and alerts on new ones.

    Spotting what is unusual needs history across scans; a single snapshot cannot show what is unusual.

    CloudCloud
  • Permission-set audit from the editor

    Audits the configured org's permission sets for powers such as Modify All Data, through your own Salesforce CLI login.

    A developer can check the org a change targets without opening another tool or sharing a token.

    VS CodePro

Proof and accuracy 7

Evidence behind every finding, an honest account of what was not checked, and less noise.

  • Proof per finding

    Every finding is proven, unproven or not checked, with the data-flow steps behind it and a severity set by who can reach it.

    Reviewers spend time on findings with evidence, and that evidence is never behind a paywall.

    CoreFree
  • Explain and proof tests

    Explains a finding in your framework, and writes runnable test cases that demonstrate eligible injection and authorization findings.

    The explanation matches your stack, and a failing test ends the argument about whether a finding is real.

    CoreFree
  • Check other tools' results

    Takes another tool's SARIF results and marks each one proven, not provable with the reason, or not checked.

    Teams with an existing scanner can sort its output by evidence instead of re-triaging every alert.

    CoreFree
  • Coverage and why-not

    Output says what the scan read and did not, and you can ask why nothing was reported at a file and line.

    A clean result on code the scanner could not read is the most dangerous false negative.

    CoreFree
  • Findings in Salesforce terms

    Each finding says who can trigger it, the door, the access mode, the data flow and the fix in Salesforce idiom.

    Admins and developers act on a sentence about their org, not on a generic rule name.

    SalesforceFree
  • Published check catalogue

    Lists every check with its id, category, default severity, what it looks for and why, and explains suspected misses.

    Buyers and auditors see exactly what is covered before they rely on a clean result.

    SalesforceFree
  • Org read coverage

    Org audits report whether each check read all, part or none of the org, instead of turning a failed read into no findings.

    A clean audit you cannot trust is worse than no audit; the read coverage tells you which one you have.

    SalesforcePro

Fixing 7

Concrete changes for each finding, checked by the detector before you accept them.

  • Fix patches

    Prints a concrete patch and remedy per finding for common vulnerability classes, and applies a strict set of safe rewrites.

    A ready patch in your own code turns a finding into a reviewable change instead of a ticket.

    CoreFree
  • Verified fixes

    Applies each proposed patch to a copy, scans again and keeps only patches that remove the finding without adding one.

    The detector, not a model, decides whether a fix worked, and your working tree is untouched until you apply.

    CoreFree
  • AI recommendations

    Ask, hunt, explain and triage with a model you choose, local by default; every AI answer is labelled advisory.

    AI helps with judgement calls while the deterministic result, its severity and the exit code stay unchanged.

    CoreFree
  • Reviewable fixes, verified AI drafts

    Generates patches, Setup links and deploy scripts, and local-model Apex patches applied only when the detector confirms them.

    Admins get the exact change to review, and nothing touches an org without a person deploying it.

    SalesforceFree
  • How to fix, per issue

    Each issue shows the Setup link, the steps and a patch to download; a fix bundle covers many issues at once.

    Admins without write access to a repository still get a precise, reviewable fix, and the org is never changed by Vulkro.

    CloudCloud
  • Quick fixes

    The lightbulb offers suppress, explain and, for clear-cut patterns, a deterministic one-line fix you accept or reject.

    Small, certain fixes take one keystroke, and nothing edits your file without your accept.

    VS CodeFree
  • Verified AI fixes in the editor

    A local model drafts a fix, offered only after a fresh scan confirms the finding is gone and the file parses.

    You review a diff the detector has already checked, instead of trusting a model's claim.

    VS CodeFree

Editor, CI and gates 16

Findings where developers work, and gates that fail a build on the right things.

  • CI gate and git hooks

    Fails a build at a chosen severity with a fixed exit-code contract, writes SARIF and JSON, and installs commit and push hooks.

    A gate that separates findings from tool errors never turns an infrastructure problem into a silent pass.

    CoreFree
  • Baseline and shared triage

    Saves today's findings as a baseline and keeps false-positive and accepted-risk decisions in one file the CLI, console and editor all read.

    Triage decisions are reviewed in pull requests like code and never have to be made twice.

    CoreFree
  • Local console

    The local console, in your browser on this machine, for browsing findings, proof and fixes on the active repository.

    Not everyone who triages lives in a terminal, and nothing leaves the machine to get a visual view.

    CoreFree
  • Release gate on new findings

    Fails a build only on findings new since a branch or commit, with a ratchet that never lets the count grow.

    Teams can gate every pull request from day one without first paying down every existing finding.

    CorePro
  • Pull-request comments

    Posts findings as inline review comments and CI annotations on GitHub, GitLab, Bitbucket and Azure DevOps.

    The finding appears on the changed line, where the author is already looking.

    CorePro
  • Change review and API diff

    Shows findings on the lines a change touched, and which endpoints were added, removed or lost protection since a ref.

    Reviewers see what this change introduced, including a new public endpoint that no rule fires on.

    CorePro
  • History, trends and hotspots

    Keeps every scan, compares any two, shows how findings moved and which files the risk keeps returning to.

    Leaders see whether risk is falling, and effort goes where findings keep recurring.

    CorePro
  • Vulkro Cloud from the terminal

    Connects the Salesforce CLI to your Vulkro Cloud workspace to work the ranked queue, triage, start cloud scans and confirm an issue is fixed.

    Developers clear the team queue without leaving the terminal, and CI can gate on open issues in the workspace.

    SalesforceCloud
  • Salesforce local console

    A local console that opens on exposure, review readiness, changes and findings, with a data access matrix and an Apex run-mode view.

    Admins who do not live in a terminal get the same results, running on their own machine.

    SalesforceFree
  • Presubmit gate and metadata review

    Fails a build only on new findings, and reports what a metadata change grants and to whom, on the pull request.

    Teams gate every change without blocking on old debt, and permission changes get read as access.

    SalesforcePro
  • Changes, history and compare

    Keeps every scan, compares any two, shows what changed in each org, accepts a baseline and sends daily and weekly digests.

    Seeing a risky change the next day beats finding it in a quarterly review.

    CloudCloud
  • VS Code, Cursor, Windsurf and VSCodium

    One command installs the extension into VS Code, Cursor, Windsurf or VSCodium, in one edition for Vulkro Core and one for Vulkro for Salesforce.

    Developers get findings in the editor they already use, from the same engine as CI.

    VS CodeFree
  • Findings on the line

    Shows findings on open and save, or, in watch mode, on every file change, with the proof tier and proof steps on hover.

    A finding fixed while the code is still open costs minutes, not a review cycle.

    VS CodeFree
  • Report export and CI parity

    Exports the same whole-project scan CI runs as SARIF or JSON, and checks that the editor view matches your CI settings.

    What a developer sees locally is what the pipeline will fail on.

    VS CodeFree
  • Salesforce in the editor

    Apex, LWC, Aura, Visualforce, Flow and metadata findings inline, with how each class runs and which profiles can call it.

    Salesforce developers see sharing and access mode while they write the class, not after deployment.

    VS CodeFree
  • Changes, history and impact views

    Sidebar views for changes, history, impact, the code graph and trends, next to the default findings views.

    Developers review their change and its reach without switching to another tool.

    VS CodePro

AI coding agents 11

The same engine as tools for AI coding agents, with evidence an agent can check.

  • MCP server for code

    Gives Claude Code, Cursor, Windsurf and other MCP clients tools to scan, explain, prove and fix, with the proof chain per finding.

    Agents get ranked findings with evidence instead of reading the codebase to search for issues themselves.

    AI coding agentsFree
  • Fix verification for agents

    An agent submits the diff it proposes; Vulkro applies it to a copy, rescans and reports whether the finding is gone.

    The detector, not the agent, decides whether a fix worked, before anything is applied.

    AI coding agentsFree
  • Check the agent's own change

    Scans the whole project but returns only findings on the lines a change added or modified.

    An agent checks its own work in one call, with answers small enough to act on.

    AI coding agentsPro
  • Code graph, change assessment and evidence graph

    Ranked call graph, blast radius before an edit, a stack trace mapped onto code, and a stable evidence document for any agent.

    Agents navigate and change code with ranked, capped answers instead of reading files to find callers.

    AI coding agentsPro
  • Write-time guard

    Hooks into Claude Code and Cursor to scan every file the agent writes, asking it to regenerate on a proven or High finding.

    Scanning becomes part of the agent's write loop, whether or not it decides to ask.

    AI coding agentsFree
  • Agent skill

    Installs a Vulkro skill for Claude Code, Cursor and Codex CLI so the agent knows when and how to run a security review.

    The agent reaches for the scanner at the right moments without a long prompt each time.

    AI coding agentsFree
  • Checks for MCP and cloned repositories

    Audits MCP configuration and MCP server source for risky setups and tool poisoning, and inspects a cloned repository before it runs.

    Assistant tooling runs with a developer's access, and it is rarely reviewed before it is trusted.

    AI coding agentsFree
  • Tools for Copilot Chat agent mode

    The extension registers scan-file and explain-finding tools that GitHub Copilot Chat agent mode can call and you can reference.

    Teams on GitHub Copilot get the same engine inside their existing chat.

    AI coding agentsFree
  • MCP server for Salesforce

    Lets an agent scan an SFDX project or metadata and list every check, offline.

    Salesforce developers using agents get platform-aware findings instead of generic code advice.

    AI coding agentsFree
  • Org and change tools for agents

    Agents read permissions, sessions, MFA and Health Check through your Salesforce CLI login, and assess a change's blast radius.

    An agent can answer what a change will touch and who holds a power, from the real org.

    AI coding agentsPro
  • Vulkro Cloud tools for agents

    An agent lists what to fix, triages, assigns, plans a fix against your local project and verifies it in your Vulkro Cloud workspace.

    Agents work the team queue, and their triage proposals still wait for a person to approve.

    AI coding agentsCloud

Team and Cloud 12

Shared issue lists, triage, roles, notifications and history for a security team.

  • Portfolio and shared console

    Rolls many repositories into one portfolio, and serves the console on a network address with a token for the team.

    A security lead responsible for many services works from one view the whole team can read.

    CorePro
  • Notifications

    Sends scan summaries to Slack, Microsoft Teams, Jira, PagerDuty and webhooks, updating Jira issues instead of duplicating them.

    Findings reach the channel the team already uses, without a ticket flood on every rerun.

    CorePro
  • Client workspaces and portfolio

    Groups projects and orgs under a named client, rolls up risk across orgs, and exports one client-ready report per client.

    Consultancies and partners manage many orgs, and each client needs its own clean deliverable.

    SalesforcePro
  • Dedicated workspace, isolated scans

    Each company gets its own workspace with its own database, storage and keys; every scan runs in parallel in its own container.

    Your org data is separated from other customers by design, and many orgs never queue behind each other.

    CloudCloud
  • Scheduled scans

    Scans each live org daily, weekly or monthly at a time and time zone you choose, or on demand.

    Posture changes every week; a schedule catches drift without anyone remembering to run a scan.

    CloudCloud
  • One issue list with stable keys

    Every finding of every kind in one list per org, each with a key, status and assignee, closed on rescan when fixed.

    Work is tracked once across scans, and a fix is confirmed by the next scan, not by a checkbox.

    CloudCloud
  • Fix first

    The org overview leads with the most severe open issues to work on next.

    A team with limited hours starts with the issues that matter most.

    CloudCloud
  • Triage with approval

    Developers mark issues in progress or fixed at once; a false positive or accepted risk waits for someone else to approve it.

    Risk is never waved away by one person, and the decision and approver are on record.

    CloudCloud
  • Rules, suppressions and custom rules

    Make any rule advisory or off for some orgs or files, and write custom org and Apex rules tested on the latest scan.

    Policy is visible and accountable, and company rules are proven against real data before they go live.

    CloudCloud
  • Roles and sign-in rules

    Built-in roles from Owner to Viewer plus your own, per-org scope, required MFA, domain and network limits and session timeouts.

    Auditors, contractors and developers see only what they need, in a workspace locked down like the org.

    CloudCloud
  • Notifications

    Sends events to Slack, Microsoft Teams, Google Chat, Discord, PagerDuty, your mail server, signed webhooks and Jira with status read back.

    Alerts reach the people on call, and a closed Jira ticket marks an issue ready to close, never closed.

    CloudCloud
  • Workspace data controls

    Set result retention, mask personal data, export the workspace, delete it, grant time-limited support access and export the activity log.

    Security and privacy teams can answer how long data is kept, who saw it and how to get it back.

    CloudCloud

Reports and compliance 9

Reports, audit evidence and standard formats you hand to someone else.

  • Executive report

    Builds an HTML report you can open in a browser or save as PDF, worst findings first.

    Clients, managers and auditors get a readable document instead of raw scanner output.

    CorePro
  • Compliance mapping and evidence packs

    Maps findings to controls in ASVS, PCI DSS, SOC 2, HIPAA, ISO 27001, NIST and GDPR, and builds audit and CRA bundles.

    Security findings become structured audit evidence without a manual spreadsheet mapping.

    CorePro
  • Evidence formats

    Writes CycloneDX and SPDX bills of materials, VEX, a cryptography inventory, an AI bill of materials, PDF, CSV and JUnit.

    Procurement, auditors and downstream customers each ask for a specific standard file.

    CorePro
  • AppExchange readiness checklist

    Maps findings to the Security Review categories and pre-submit checklist, and attests Apex test coverage against the bar.

    ISVs see where the package stands before submitting, instead of after a failed review.

    SalesforceFree
  • AppExchange submission packet

    Builds the readiness report and packet: blocking fixes by effort, drafted false-positive justifications and a bill of materials.

    A failed Security Review means another round; a complete, evidenced packet reduces the back and forth.

    SalesforcePro
  • Salesforce compliance evidence

    Builds auditor packages for SOC 2, HIPAA and PCI, a GDPR record of processing, a HIPAA safeguard matrix and hashed attestations.

    Compliance teams get evidence generated from the org and code, with a hash to show it was not edited.

    SalesforcePro
  • Org posture report and SIEM events

    Generates a shareable posture report for a live org, and writes audit findings as OCSF events with MITRE ATT&CK techniques.

    Leadership gets one document, and Salesforce posture joins the rest of your security reporting.

    SalesforcePro
  • Compliance, reports and exports

    Control status with the issues behind it, hashed PDF and CSV evidence packs, a security report, masked CSV and OCSF exports.

    Auditors see which open issue fails which control, and results leave in the shape each audience needs.

    CloudCloud
  • Review readiness

    An internal review view plus the AppExchange checklist, report and packet, from the latest scan.

    ISVs track Security Review readiness on every scan instead of in a rush before submission.

    CloudCloud

Supply chain and secrets 9

Dependencies, bills of materials, containers, credentials and what enters a project.

  • Dependency CVEs with reachability

    Matches dependencies against offline vulnerability data, tags whether your code reaches each one, and raises known-exploited ones.

    A vulnerable library you never call is a scheduled upgrade; an exploited one on a live path is an incident.

    CoreFree
  • Secrets in the working tree

    Finds credentials committed in the files on disk, with optional live validation that is off by default.

    A leaked key can bypass every other control, and it is cheapest to catch before the push.

    CoreFree
  • Malicious-code checks

    Flags malicious install scripts in every scan, and surfaces credential theft, reverse shells and obfuscation in source you have not run.

    Supply-chain attacks run at install time, before review. Vulkro never certifies code as safe.

    CoreFree
  • Package and extension vetting

    Checks dependency lists for malicious, hallucinated and typosquatted names, and installed extensions for risky permissions.

    An invented package name is a name an attacker can register, and extensions run with a developer's access.

    CoreFree
  • Secrets in git history

    Finds credentials that were committed and later removed, still recoverable from the repository history.

    Deleting a key from the latest commit does not revoke it; anyone with the history still has it.

    CorePro
  • Bill of materials and matching

    Lists every dependency in standard bill-of-materials formats, and checks an external one against local vulnerability data.

    A current inventory is the first thing asked for when a new advisory lands, including for vendor components.

    CorePro
  • Container scanning

    Checks the operating-system and application packages inside a built image against local vulnerability data, without pulling from a registry.

    The image is what runs in production, and it carries packages the source manifests never list.

    CorePro
  • Advisory response

    Answers whether a named package or advisory is anywhere in the project, across lockfiles and imports, in seconds.

    When an advisory drops, the first question is whether you are exposed, and it needs a fast, exact answer.

    CorePro
  • Package and static-resource CVEs

    Checks managed packages and JavaScript in static resources against offline vulnerability and end-of-life data, and builds a data dictionary.

    Old JavaScript in a static resource is a common, overlooked way to ship a known vulnerability.

    SalesforceFree

Offline and privacy 4

Local analysis, an air-gap switch, and no model in the scan.

  • Air-gap switch

    One flag or environment variable blocks every outbound network call for a run; a local model is still allowed.

    Regulated and classified environments need a guarantee, not a setting buried in a config file.

    CoreFree
  • Air-gapped vulnerability data

    Keeps vulnerability data current on Free, and applies updates from an offline file on machines with no internet.

    An offline scanner that goes stale is a liability; this one can be updated without a network.

    CoreFree
  • No model in the scan

    The scan engine calls no model and sends no code anywhere, and the optional AI layer is local by default.

    Results can be reproduced, audited and gated on, and detection costs no model tokens.

    CoreFree
  • Local analysis, your own org login

    Source, paths and findings stay on your machine; live-org reads go through your own Salesforce CLI login and change nothing.

    No new integration user, no token held by a vendor, and no org data sent anywhere for analysis.

    SalesforceFree

03Languages

Language coverage and analysis depth

Where data flow crosses files and where it stops at one function, said plainly.

Vulkro Core
Analysis depth per language
LanguageRoute mappingentry pointsData flow, same filesource to sinkData flow, across filesvia the call graphFramework awarenessrouters, ORMsDedicated checkslanguage rules
PythonDjango, Flask, FastAPI
JavaScriptExpress, Koa, Next.js
TypeScriptExpress, NestJS, Next.js
Gonet/http, Gin, Echo, chi
Javasame-file data flow only
PHPsingle function; Laravel, Symfony sources
Csingle function
C++the C rules run here too
Apexentry points, not URL routes · Vulkro for Salesforce
Terraform, Dockerfileconfiguration, not data flow
Full: runs on every scan of that language Partial: limited to the cases in the row Not analysed at this depth today

See it on your own code and your own org.