Skip to main content

Use case · Application and API teams

Know every endpoint, and which ones an attacker can reach.

Vulkro reads your routes and shows what is open, what needs a login, and where request data ends up. Each finding comes with the path from the route to the risky call.

Vulkro Core · VS Code extension

vulkro · orders-apijs-taint-sql-001
CriticalProven

Anyone can run their own SQL through the order search

  1. Entry pointsrc/routes/orders.ts:4
    router.get('/api/orders', async (req, res) => {Express route · no sign-in needed
  2. Callsrc/routes/orders.ts:5
    const rows = await searchOrders(req.query.q)the search term passed straight on
  3. Sinksrc/services/orders.ts:4
    pool.query("SELECT * FROM orders WHERE customer_name LIKE '%" + term + "%'")SQL built from the request, no binding
Who can reach it
Anyone, no sign-in
What is at stake
Every customer's data
Guards on the path
None. The value is never bound
Disposition
Proven: traced from the request to the query
Fix
Bind the value: pool.query('... LIKE $1', [`%${term}%`])

01The problem

Most APIs have endpoints nobody documented

Most API breaches go through an endpoint the team forgot existed, or one that trusts the caller too much.

  • Routes nobody listed

    Endpoints added in a hurry, debug routes left in, and tools an AI agent can call never make it into the spec.

  • Login checks with no ownership check

    A route that only asks "are you signed in?" hands any user any record whose id they can guess.

  • Findings without a path

    A scanner that flags a query without showing how request data reaches it leaves you to trace it by hand.

03The workflow

Steps from first scan to fix

  1. 01

    Map the surface

    List every endpoint the code declares, with the guards on each, before any check runs.

    Vulkro Core
  2. 02

    Scan for what is reachable

    Follow request data from each route into queries, commands, files and outbound requests.

    Vulkro Core
  3. 03

    Read the path

    Each finding shows the entry point, every hop and the missing guard, so the fix goes in the right place.

    Vulkro Core
  4. 04

    Check who can call what

    See the login level per endpoint and spot routes that need more than a session.

    Vulkro Core
  5. 05

    Catch it on save

    Developers see the same findings in the editor before the pull request.

    VS Code extension

04What you get

What you get

Inventory
Every route the frameworks declare, with its handler and guards, including the ones nobody documented.
Proof
Injection reached from a route comes with the trace from request to sink.
Honest about limits
Ownership checks Vulkro cannot decide from source are reported as not checked, never as passed.
Frameworks
Express, Koa, NestJS, Next.js, FastAPI, Django, Flask, Java web routes, and Go net/http, Gin, Echo and chi.
Offline
Your code never leaves the machine. No AI in detection.

Questions

Common questions

Does it test a running API?
No. Vulkro reads the source, so it sees routes that are hard to reach from outside, and it never sends traffic to your service.
Can it prove a broken object-level authorization bug?
It flags lookups by id with no ownership check, and says plainly that it cannot decide them offline. They are reported for review and never fail a build. Injection and similar flows from a route are proven with a data-flow trace.
What is free?
The endpoint inventory, every check and the proof behind each finding are free. The login-level matrix, the inferred OpenAPI spec and the endpoint diff between two versions are Pro.

Find the API endpoints an attacker can reach, and fix them.