| title | Vigolium |
|---|---|
| description | High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision |
| mode | wide |
Vigolium is a high-fidelity web vulnerability scanner that fuses agentic AI with native speed, modularity, and precision. It combines deterministic multi-phase scanning with AI-driven autonomous analysis to deliver comprehensive security coverage, from injection flaws and access control issues to framework-specific vulnerabilities and blind out-of-band attacks.
The platform is built around three key components that work together to provide a complete vulnerability scanning solution.
The core scanning engine. Handles all scanning logic, module execution, and heavy lifting, from content discovery and browser-based spidering to active fuzzing and agentic AI scanning. A self-hosted dashboard for visualizing scan results, managing projects, and tracking findings across your infrastructure. Deploy it on your own servers for full control over your data. A cloud-based solution that provides managed scanning, team collaboration, and centralized reporting without the overhead of self-hosting. ```bash curl -fsSL https://vigolium.com/install.sh | bash ``` Installs `~/.local/bin/vigolium` and adds it to your shell profile. The installer verifies the SHA-256 checksum before installing. ```bash npm install -g @vigolium/vigolium ``` Thin launcher that pulls the prebuilt binary for your platform as an optional dependency (Node 16+). ```bash bun add -g @vigolium/vigolium ``` Installs the Vigolium launcher globally with Bun. Same prebuilt-binary launcher as the npm install path; Bun is just a faster package manager. ```bash brew install vigolium/tap/vigolium ``` Installs the latest release from the Vigolium tap on macOS and Linux. Upgrade with `brew upgrade vigolium`. ```bash docker pull j3ssie/vigolium:latest docker run --rm j3ssie/vigolium:latest scan -h ``` The container entrypoint is the `vigolium` binary, pass any subcommand directly. ```bash git clone https://github.com/vigolium/vigolium.git cd vigolium make build ``` Requires Go 1.27+, Bun 1.3.11+, `git`, and `make`. Always use `make build` (not `go build`), it injects version metadata. ```powershell npm install -g @vigolium/vigolium ``` Vigolium ships a native **windows/amd64** build since v0.4.3. The npm launcher is the easiest path; alternatively download `vigolium__windows_amd64.zip` from the [releases page](https://github.com/vigolium/vigolium/releases) and put `vigolium.exe` on your `PATH`. `curl | bash` and Homebrew are POSIX-only, and `vigolium update` cannot self-update on Windows — it prints the zip to download instead. Windows on ARM installs the x64 build and runs it under emulation.For a guided walkthrough including validation and your first scan, see the Quickstart.
Agentic scanning uses AI agents to drive or augment the scanning process. Invoked via vigolium agent <mode>. All AI dispatch is routed through the in-process olium engine, which supports eleven providers: openai-codex-oauth, anthropic-api-key, anthropic-oauth, openai-api-key, openai-responses, anthropic-cli, anthropic-claude-sdk-bridge, anthropic-compatible, anthropic-vertex, google-vertex, and openai-compatible (Ollama / OpenRouter / LM Studio / vLLM).
| Mode | Command | Description |
|---|---|---|
| Query | vigolium agent query |
Single-shot prompt execution. Good for code review, endpoint discovery, secret detection. No network scanning. |
| Autopilot | vigolium agent autopilot |
Autonomous AI-driven pentest. The olium engine discovers endpoints, runs scans, and triages findings on its own, driving Bash, file ops, and first-class Vigolium tools until it calls halt_scan. Supports diff-focused runs (--diff), prior/knowledge-base context, intensity presets, and durable-mode resume. |
| Swarm | vigolium agent swarm |
AI-guided pipeline for targeted single-request or full-scope (--discover) scanning. The master agent selects modules, generates custom JS scanner extensions, runs code audit and SAST, executes scans, and triages results, with native Go handling the heavy lifting while AI intervenes at checkpoints. |
| Audit | vigolium agent audit |
Unified whitebox security audit driver (lite / balanced / deep). Runs the embedded vigolium-audit harness, the standalone piolium harness, or both side-by-side under one parent scan. |
| Piolium | vigolium agent audit --driver=piolium |
Pi-native whitebox audit driver (separate install). Up to 17 phases at deep, the most thorough audit available. |
| Olium | vigolium olium / vigolium ol |
Interactive TUI chat or one-shot non-interactive prompt, the underlying agent runtime. |
All scan-oriented modes support --source for source-aware analysis and store session artifacts (plans, extensions, output) under ~/.vigolium/agent-sessions/.
Deterministic, multi-phase vulnerability scanning via vigolium scan. Fast, modular, and repeatable, runs content discovery, browser spidering, SPA crawling, and active/passive dynamic-assessment phases with 323 scanner modules (207 active, 116 passive).
| Category | Coverage |
|---|---|
| Injection | XSS (reflected, DOM-based, SSR hydration), SQL injection (error-based, boolean/time-blind), NoSQL injection, SSTI/CSTI, CRLF injection, command injection, XXE/SAML, prototype pollution |
| Access Control | CSRF, IDOR, authorization bypass, mass assignment, forbidden bypass, HTTP method tampering |
| File & Path | LFI, path traversal, file upload flaws, directory listing, backup/sensitive file discovery, path normalization bypass |
| API & Protocol | GraphQL security suite (introspection, SQLi, IDOR/BOLA, DoS, batching), MCP server security (tool/resource/prompt fuzzing, session & origin checks), SSRF (direct & blind), open redirect, HTTP request smuggling, JWT vulnerabilities, JSONP callback, WebSocket security, race conditions |
| Framework-Specific | Spring Boot, Django, Laravel, Rails, Express, Next.js, Nuxt, Remix, ASP.NET/Blazor, IIS, Flask, FastAPI |
| Enterprise & SaaS Platforms | Adobe Experience Manager (dispatcher bypass, sensitive servlets, RCE-surface exposure, CVE probes), Salesforce Experience Cloud (Aura object/record exposure, guest Apex execution, Lightning debug mode), ServiceNow (widget & KB data exposure), Microsoft Power Pages (Dataverse Web API exposure) |
| CMS | WordPress (XML-RPC, user enum, AJAX exposure), Drupal, Joomla, CMS installer exposure |
| Cloud & Infra | Firebase (RTDB, storage, auth, functions), cloud storage listing/takeover, default credentials, web cache poisoning, CORS misconfiguration |
| Out-of-Band | Blind vulnerabilities via OAST callbacks (blind SSRF, blind SSTI, OAST probes) |
The CLI is the heart of Vigolium, powering all scanning operations with two complementary modes:
- Value-aware mutation: classify parameter values by semantic type and generate intelligent mutations
- Multi-phase pipeline: external harvesting, content discovery, SPA crawling, and audit controlled by strategy presets
- Scanning profiles: bundle strategy, pace, scope, and module config into a single YAML file
- Multiple input formats: URLs, OpenAPI/Swagger, WSDL/SOAP, Postman, Burp Suite, cURL, Nuclei JSONL
- Browser-based spider: Chromium-driven crawler with SPA support, form filling, and JS analysis
- Multi-session authentication: inline sessions, session files, or full auth configs with login flows and token extraction
- JavaScript extensions: custom modules and hooks via embedded JS engine
- Source-aware agentic scan: pair
--sourcewithswarm,autopilot, orauditfor code-context-aware AI scanning and audit - Concurrent architecture: configurable worker pool with per-host rate limiting and hybrid queue
- HTML reports: self-contained HTML reports with sortable/filterable tables
- API server mode: REST API with Swagger UI, multi-format ingestion, transparent HTTP proxy
A self-hosted web dashboard that provides a visual interface for managing and analyzing your scan data. Deploy Workbench on your own infrastructure to maintain complete control over your vulnerability data while giving your team an intuitive way to:
- Browse and filter scan findings with severity breakdown per project
- Track vulnerability trends across repositories and scan history
- Manage multiple projects with multi-tenancy support
- View detailed request/response evidence for each finding
A cloud-based solution for teams that want the power of Vigolium without managing infrastructure. Console is the upgraded, fully-featured version of Vigolium, managed scanning, centralized reporting, team collaboration, and extra features layered on top of the open-source core, so you can focus on fixing vulnerabilities instead of maintaining tooling.
Check out the Cloud Console at [console.vigolium.com](https://console.vigolium.com/).| I want to... | Start here |
|---|---|
| Get up and running quickly | Quickstart |
| Understand how native scanning works | How It Works |
| Pick the right scanning strategy | Strategies |
| Dive into individual scan phases | Phases, discovery, spidering, audit, extension, SPA |
| Try agentic scanning | Agent Mode |
| Let AI drive scans autonomously | Autopilot |
| Run multi-phase AI + native pipelines | Swarm |
| Audit source code in depth | Agentic Security Audit |
| Chat with the agent runtime | Olium |
| Run Vigolium as an API server | Server Mode |
| Tweak scan settings | Configuration |
| Export and format results | Output & Reporting |
| Write custom JS extensions | Writing Extensions |
| Browse the REST API | API References |
For any inquiries, feel free to contact us at contact@vigolium.com.












