
BugBounty Arsenal
Free open-source web scanner with an AI fix advisor
4 followers
Free open-source web scanner with an AI fix advisor
4 followers
Free, open-source web security scanner β self-hostable with one `docker compose up`. Not just "here's what's broken": an AI advisor tells you how to fix each finding (and, for authorized testing, how to reproduce it). Plus a live feed of new bug bounty programs across HackerOne, Bugcrowd, Intigriti & YesWeHack, scheduled scans that alert only on new findings, CI/CD gating + SARIF export, and 53 detectors overhauled to cut false positives. Free, no card, no lock-in.






Hey Product Hunt π
I'm a solo dev and I've been building BugBounty Arsenal in the open. The idea started simple: a scanner shouldn't just dump findings on you and walk away.
So the last few weeks I added an AI advisor that, for every finding, tells you how to fix it (with code/config) and β for authorized testing β how to reproduce it for your report. It's guidance for you to apply, never changes to the target.
I also added a live feed of newly launched bug bounty programs right on the homepage, because half the game is being early.
And I did a big false-positive cleanup pass β a real scan that used to return 100 noisy "highs" now returns a handful of real findings.
It's free, open-source and self-hostable. I'd love brutal feedback: what's noisy, what's missing, what would make it part of your workflow?
Thanks for taking a look π