npm v1.6.0JS/TS livelocal scanApache-2.0

Security evidence for AI-built software

The scanner is free. The proof is the product.

Verglos scans AI-assisted JavaScript and TypeScript repos for the security mistakes agents keep writing, then turns the result into evidence a founder, agency, or engineering team can actually use.

$ npx verglos

scanned 1,247 files in 42s

report: verglos-report.html + verglos-report.json

verglos scan

critical / D4-004

credential-shaped value in source

high / AI-005

unresolved package name in lockfile

fix

move to env, rotate, pin dependency

0/ 100

Critical risk

AI-authored estimate41%
Evidence artifactlocal

1.6.0

npm release

published package, local CLI, Node 20+

10

risk domains

secrets, deps, injection, auth, data, runtime

300

repo campaign

ICP scan campaign used to shape the product

0

source upload

V1 scanner writes reports on your machine

10-domain scanner

Built from the bugs AI agents make cheap to create.

The domain model stays explicit: injection, auth, access control, cryptography, misconfiguration, supply chain, API surface, data exposure, runtime, and monitoring.

Domain 01 of 10

Injection & input flaws

Critical

Every piece of user input is a weapon if it reaches a dangerous sink unsanitised. We trace source-to-sink across your codebase — SQL, NoSQL, command exec, XSS, SSTI, path traversal — and flag the concatenations, spreads, and eval calls that turn a request into a takeover.

SQL / NoSQL
Command exec
XSS (stored / reflected / DOM)
SSTI

sample finding

element.innerHTML = req.query.name

app/user/[id]/page.tsx:42

Evidence path

Enterprise thinking without pretending to be enterprise theater.

Verglos is designed to move from local findings to durable proof: CI enforcement, monitoring, signed attestations, verification URLs, SBOMs, and client-ready reports.

01

Scan before handoff

Run the CLI locally and get findings, paths, snippets, fixes, score, and AI-risk signal before handoff or diligence.

02

Separate alerts from evidence

The report is designed to be read by builders first, then turned into proof for clients, procurement, or internal security review.

03

Graduate into continuity

Pro and Studio move beyond one-off scans: CI thresholds, monitoring, activation, attestations, verify URLs, and white-label reports.

Why it matters

The invisible cost you're paying today.

Not the bugs Verglos finds — the ones you don't. Every AI-assisted stack carries a handful of buried failure modes that won't announce themselves. Here's what changes when you can see them.

$29/mo · less than one hour of dev time

The developer

You stop needing to remember.

The scan you meant to run last Tuesday is the one that would have caught the CVE that shipped today. Verglos watches your dependency tree hourly and emails the moment a critical is published. No calendar reminder, no manual re-scan, no discipline debt.

The agency

Client handover without the awkward Zoom.

Every AI-built app you ship carries the same buried defaults — wildcard CORS with credentials, jwt.verify accepting alg=none, MD5 password hashes. Your client's security review will find them. Better they surface at build time on your machine than in a pen-test report three months in.

The founder

The 3am email you don't want but need.

Log4j, event-stream, whatever ships next — critical CVEs land at 2am UTC on a Sunday and your customer notices before you do. Verglos flips that: an email arrives within the hour of publication, deduped so you get it once, delivered through email, Slack, or webhook. Cheaper than one bad Monday.

The agent user

AI can't ship the same bug twice.

Your coding agent will write Math.random() for a session token because a tutorial did. It'll suggest a package name because it hallucinated one. Verglos plugs into Cursor, Claude Code, Windsurf, and Cline as an MCP tool — the agent asks Verglos before writing risky code or installing a suspect package. Correction happens inside the flow, not after the merge.

Language coverage

JavaScript and TypeScript first.

JS/TS is live today because that is where Verglos has real detector coverage, package analysis, and provenance signal. Other stacks stay on the request list until they are actually supported.

Live now

JavaScript and TypeScript first.

JavaScriptJS
TypeScriptTS

Covers Node.js, Next.js, React, Express, Fastify, and npm workspaces.

PythonGoRubyJavaPHPRustC# / .NETSwiftKotlin
Request your stack →

Plans

Free is the complete local scanner.

Run it as many times as you want locally. Paid tiers are for teams that need enforcement, monitoring, evidence, handoff, and readiness workflows around the scan.

Free plan

Unlimited local scans. Full findings. Full paths. Local HTML and JSON reports. No account required.

Live

Free

$0

For: Developers, founders, agencies

Use: Unlimited local repo checks.

Unlimited local scans. No account, no source upload, no paywall for paths or line numbers.

  • /Full 10-domain static scan
  • /Security score /100
  • /All file paths + line numbers
  • /Secret detection, entropy, git-history scan
  • /Dependency CVE audit via OSV
  • /AI-authored code detection
  • /Slopsquat / hallucinated-package check
  • /Local HTML + JSON report
  • /Pre-commit hook
  • /MCP server
  • /CI blocks on criticals
  • /Unlimited local use
Run from npm

Live

Pro

$29/mo

For: Serious solo devs and small teams

Use: CI discipline and ongoing dependency risk.

For teams that want the scanner to keep enforcing standards after the first local report.

  • /Everything in Free
  • /CI score thresholds
  • /Continuous CVE monitoring (hourly)
  • /Email / Slack / webhook alerts
  • /Agent-surface rule pack (MCP configs)
  • /API-hardening rule pack
  • /Deep-auth rule pack (JWT / cookies / hashes)
  • /verglos fix — framework-aware headers
  • /30-day score-history dashboard
  • /Offline-safe license (Ed25519 signed)
Start Pro

Validation

Studio

$199/mo

For: Agency owners and delivery leads

Use: Client handoff, liability, and proof of AI-built work.

Agencies do not need another noisy scanner. They need client-ready evidence that helps a project pass handoff.

  • /Everything in Pro
  • /Signed attestations
  • /Public verify URLs
  • /White-label client reports
  • /SBOM export
  • /License-risk flagging
  • /verglos rotate
  • /Rotation runbooks
  • /1-year evidence history
  • /Client-facing share links
Discuss Studio

Planned

Compliance

$499/mo

For: Founders and heads of engineering

Use: Procurement, SOC 2 readiness, diligence.

For teams preparing security answers before an auditor, customer, or enterprise review forces the conversation.

  • /Everything in Studio
  • /SOC 2 readiness assessment
  • /GDPR data-map report
  • /Security posture PDF
  • /Evidence archive
  • /Audit trail
  • /Metered AI triage
  • /Threat-intel feed
  • /Priority support
  • /3-year evidence history
Discuss Compliance
CapabilityFreeProStudioCompliance
Full 10-domain static scanYesYesYesYes
All file paths and line numbersYesYesYesYes
Local HTML + JSON reportYesYesYesYes
AI-authored code detectionYesYesYesYes
Slopsquat / hallucinated package checkYesYesYesYes
MCP serverYesYesYesYes
CI score thresholdsCriticals onlyYesYesYes
Continuous CVE monitoring + hourly alertsNoYesYesYes
Email / Slack / webhook alertsNoYesYesYes
Agent-surface rule pack (Cursor / Claude Code / Windsurf / Cline)NoYesYesYes
API-hardening rule pack (rate limit, body size, CORS+creds)NoYesYesYes
Deep-auth rule pack (JWT / cookies / password compare / weak hashes)NoYesYesYes
Score-history dashboardNo30 days365 days3 years
verglos fix (framework-aware headers)NoYesYesYes
Signed attestationsNoNoPlannedPlanned
Public verify URLNoNoPlannedPlanned
White-label reportsNoNoPlannedPlanned
SBOM + license riskNoNoPlannedPlanned
SOC 2 readiness outputNoNoNoPlanned

Top Notchh operating stamp

Built by a product company, not a scanner content farm.

Top Notchh Solutions builds practical software products from real operational pain. Verglos is the security-evidence product in that portfolio: specific, local-first, honest about maturity, and built to become infrastructure for AI-assisted delivery.

Founder-led product judgment
Reusable scanner infrastructure
Evidence before decoration

From the Journal

Research and product notes.

Original research from the Verglos scan campaign, positioning notes, and product decisions — published on the Top Notchh Journal.

Read the full Journal →

FAQ

Boundaries make the product stronger.

Is Verglos just another scanner?+

No. The scanner is the entry point. Verglos is built around evidence: AI-code risk signal, report artifacts, MCP guardrails, CI enforcement, and client-ready proof.

Does Verglos upload source code?+

The V1 scan runs locally and writes local HTML and JSON reports. Networked flows are explicit: login, activation, monitoring registration, and future hosted evidence.

Which languages are supported today?+

JavaScript and TypeScript are live. Other language icons are request-list indicators, not shipped coverage.

Who is behind Verglos?+

Verglos is built by Top Notchh Solutions, an AI-native product company building practical software products from real operational problems.