EveryDev.ai
Subscribe
Home
Tools

4,020+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2782
  • Coding1973
  • Infrastructure825
  • Projects603
  • Marketing598
  • Research520
  • Analytics468
  • Design462
  • MCP419
  • Testing346
  • Security323
  • Data305
  • Integration224
  • Prompts220
  • Communication210
  • Extensions196
  • Learning179
  • Voice175
  • Commerce160
  • DevOps135
  • Web95
  • Finance31
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. Xalgorix
    Xalgorix icon

    Xalgorix

    Security Testing
    Featured

    Xalgorix is an autonomous AI pentesting platform that runs a 22-phase offensive methodology against apps, APIs, and source code, then re-exploits every candidate finding so reports contain proven vulnerabilities instead of unverified alerts.

    Visit Website

    At a Glance

    Pricing
    Open Source
    Free tier available

    Open-source engine you install and run yourself, with your own model provider

    Starter: $16/mo
    Pro: $39/mo
    Team: $159/mo
    +2 more plans

    Engagement

    Available On

    Linux
    macOS
    Web
    API
    CLI

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Security TestingApplication SecurityCode Security

    Alternatives

    DepthfirstArgusRedAstra Security
    Developer
    XalgorixRemote-first; legal entity in the EUEst. 2021

    Listed Sep 2026

    About Xalgorix

    Xalgorix is an autonomous AI penetration testing platform that tests web applications, APIs, and source code, then tries to reproduce every candidate finding before it reaches a report. An LLM-driven agent works through a fixed offensive methodology, and a separate verification step re-exploits what it found. It is published as an Apache-2.0 licensed Go and TypeScript project that teams can self-host, and the same engine also runs as a managed cloud service.

    What It Is

    The project describes itself as an open-source AI pentester that proves vulnerabilities rather than guessing at them. Instead of matching signatures or templates, the agent reasons about authentication flows, business logic, and access control, chaining steps the way a human tester would. Coverage spans injection, SSRF, IDOR and broken access control, file upload, deserialization, race conditions, and subdomain takeover, among others. Findings carry CVSS scores, evidence, and remediation guidance, and can be exported as branded PDF reports.

    The 22-Phase Methodology

    Every engagement is organized into 22 numbered phases, running from reconnaissance through directory discovery, CORS and cookie analysis, session testing, cloud and infrastructure checks, and a final report. Output from each phase feeds the next, so reconnaissance results shape later exploitation attempts. Operators can run the full sweep or select a subset when an engagement only calls for certain phases.

    Verification Instead of Triage

    Phase 20 is dedicated to exploit verification. An independent verifier re-tests each candidate finding, and the vendor states that anything it cannot reproduce is flagged for review rather than reported as confirmed. That is the design decision separating Xalgorix from template scanners, trading runtime and depth for a much shorter list to triage. Payloads are described as non-destructive, with configurable rate limits, proxy rotation, and circuit breakers intended to make runs safe against staging and production systems.

    Self-Hosted or Managed

    The self-hosted build runs a local dashboard and REST API on your own machine, with a bring-your-own-model setup supporting OpenAI, Anthropic, DeepSeek, Gemini, Groq, Ollama, and MiniMax, plus any OpenAI-compatible gateway such as LiteLLM. The documentation states that no target data, keys, or findings leave your infrastructure. The managed cloud version removes setup and model-key management, routes across frontier models per phase, and adds scheduling, team workspaces, and out-of-band infrastructure for blind SSRF and RCE testing.

    Code Scanning and Pull Request Reviews

    Xalgorix also scans code directly. Source review mode traces user input from entry point to dangerous sink without a running target, while provision mode builds and runs the application locally, then pentests the instance it started. A GitHub App reviews pull request diffs and posts findings as a single comment that updates in place on new commits, with no workflow file or API key to manage, and a GitHub Action can fail a build when verified findings cross a severity threshold the team sets.

    Xalgorix - 1

    Community Discussions

    Be the first to start a conversation about Xalgorix

    Share your experience with Xalgorix, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Self-Hosted

    Open-source engine you install and run yourself, with your own model provider

    • Apache-2.0 licensed engine, self-hosted on your own infrastructure
    • All 22 methodology phases and exploit verification
    • Bring your own LLM provider and API key
    • Local web dashboard, REST API, and WebSocket telemetry
    • Branded PDF reports and built-in scheduler
    FREE

    GitHub App

    Automatic pull request security reviews posted as a GitHub comment

    • Diff-scoped security review on every pull request
    • Covers injection, broken auth and IDOR, SSRF, secrets, and unsafe patterns
    • Comment @xalgorix review to re-run on demand
    • Updates its review comment in place on new commits
    • No workflow file, API key, or account required

    Starter

    Hosted cloud plan for indie developers running regular scans

    $16/mo
    billed annually
    $20/mo monthly
    • 50 scan credits per month
    • 1 concurrent scan
    • All 22 phases and exploit-verified findings
    • Branded PDF reports and public share links
    • Daily scheduled scans
    • API access
    • Email and Discord notifications
    • Email support within 48 hours

    Pro

    Popular

    Hosted cloud plan for founders and security engineers shipping continuously

    $39/mo
    billed annually
    $49/mo monthly
    • 200 scan credits per month
    • 3 concurrent scans
    • All 22 phases and exploit-verified findings
    • Branded PDF reports and public share links
    • Daily scheduled scans
    • API access
    • Slack, Discord, and email notifications
    • Email support within 24 hours

    Team

    Hosted cloud plan for security teams scanning many properties

    $159/mo
    billed annually
    $199/mo monthly
    • 1000 scan credits per month
    • 5 concurrent scans
    • All scan modes plus priority queue
    • Branded PDF reports with custom logo
    • Password-protected share links
    • Hourly scheduled scans
    • Audit log and 10x API rate limit
    • Email support within 4 hours

    Enterprise

    Custom-priced tier for organizations standardizing on exploit-verified testing

    Custom
    contact sales
    • Everything in Team
    • SSO/SAML and SCIM provisioning
    • Self-hosted or private deployment
    • Volume credits and higher concurrency
    • RBAC, audit log, and SSO-enforced workspaces
    • DPA, security review, and SLA
    • Annual invoicing via ACH, wire, or PO
    • Custom SIEM, GRC, and ticketing integrations
    • Dedicated support and onboarding

    Credit Pack

    One-time credit packs starting at a single credit, with no subscription required

    $1
    one time
    • 1 credit for $1
    • 10 credits for $9
    • 50 credits for $29
    • 200 credits for $99
    • 1000 credits for $399
    • Credits never expire
    • Stacks with any subscription and is consumed after monthly credits
    View official pricing

    Capabilities

    Key Features

    • Autonomous LLM agent that runs a 22-phase penetration testing methodology
    • Dedicated exploit verification phase that independently reproduces each finding
    • Reasoning over auth flows, business logic, IDOR/BOLA, and chained exploits
    • Single target, wildcard/multi-target, and browser-assisted DAST scan modes
    • Source code scanning from a Git URL, local path, or uploaded archive
    • Provision mode that builds and runs an app locally, then pentests it
    • GitHub App that reviews pull request diffs and comments findings
    • GitHub Action that fails builds at a chosen severity threshold
    • Live WebSocket telemetry of tool calls, agent messages, HTTP, and LLM activity
    • Findings management with CVSS scoring, severity filters, and deduplication
    • Branded PDF reports with executive summary, proof of concept, and remediation
    • Scheduled recurring scans and resumable scan persistence
    • REST API and signed scan.completed webhooks
    • Bring-your-own-LLM support across OpenAI, Anthropic, DeepSeek, Gemini, Groq, Ollama, and MiniMax
    • Self-hosted local dashboard with Docker images for amd64 and arm64
    • Configurable rate limits, proxy rotation, and non-destructive payload safeguards

    Integrations

    GitHub
    GitHub Actions
    Docker
    Slack
    Discord
    Telegram
    AgentMail
    Caido
    LiteLLM
    OpenAI
    Anthropic
    Google Gemini
    DeepSeek
    Groq
    Ollama
    MiniMax
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate Xalgorix and help others make informed decisions.

    Developer

    Xalgorix Team

    Xalgorix builds an autonomous AI penetration testing platform, released as an Apache-2.0 open-source project and also offered as a managed cloud service. It is founder-led by Krishna Kumar (@xalgord), a web application penetration tester and bug bounty hunter who describes the tool as an outgrowth of his own engagement workflow: automating reconnaissance, injection sweeps, and evidence collection so the harder bugs get more attention.

    Founded 2021
    Remote-first; legal entity in the EU
    9 employees
    Read more about Xalgorix Team
    WebsiteGitHubLinkedInX / Twitter
    1 tool in directory

    Similar Tools

    Depthfirst icon

    Depthfirst

    AI-native security platform that analyzes code, business logic, and infrastructure to find real vulnerabilities and reduce false positives.

    ArgusRed icon

    ArgusRed

    ArgusRed is an AI-powered automated penetration testing tool that scans your code repository, reproduces real exploits in a sandbox, and delivers confirmed breaches with ready-to-merge fixes.

    Astra Security icon

    Astra Security

    Astra Security is a continuous penetration testing platform offering PTaaS, DAST scanning, API security, and cloud vulnerability scanning for engineering teams.

    Browse all tools

    Related Topics

    Security Testing

    Tools for automated security testing and penetration testing.

    19 tools

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    125 tools

    Code Security

    Tools that analyze code for security vulnerabilities and issues.

    56 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions