Stop chasingwrong!
malware. Find
what let it in.

Malware scanners tell you you've been hacked. sec-scan finds the vulnerable code that let it happen so you can fix the cause, not just clean up the mess.

See the difference

Free during preview - no credit card needed.

sec-scan
$ sec-scan ./shop-project
Scanning 247 PHP files...
Phase 1━━━━━━━━━━done214 clean · 33 suspect
Phase 2━━━━━━━━━━done30 clean · 3 vulns
criticalsearch.phpsqli in your code
highupload.phpunrestricted upload
mediumproxy.phpssrf via user input
Done. 3 vulnerabilities in your code.
269,489
Files analyzed
174
Vulnerabilities found

Malware scanners are not enough

Finding injected webshells means you're already compromised. sec-scan finds the vulnerabilities in your own code that made the attack possible.

Other scannerssec-scan
Detect injected webshells & backdoors
Find SQL injection in your code
Find SSRF & insecure file operations
Find unrestricted file uploads
Understand OXID eShop & Shopware patterns
When it helps After breach Before breach

How it works

01

Create an account

Sign up and generate your API token. Takes less than a minute.

02

Scan your codebase

Point the CLI at any PHP directory. Batching, uploads, and caching are handled automatically.

03

Fix before you're hacked

Review vulnerabilities in your code. Filter by risk, see exactly which line is the problem, fix the root cause.

What makes sec-scan different

Built from years of hosting PHP shops - not from a textbook.

Only ~1%
need deep analysis

Fast without cutting corners

Quick triage filters 99% of clean files. Only suspicious code gets the full scan - accurate results without the wait.

Near zero
false positives

Your framework, understood

Trained on OXID, Shopware, and Magento internals. Knows the difference between an ORM property and a SQL injection.

Efficient
on every re-scan

Scan once, share everywhere

Every file cached globally by content hash. Re-scans, CI runs, and team sharing return results in milliseconds.

Built by the ScaleCommerce team

From the people who host and secure e-commerce shops

sec-scan is built by the team behind ScaleCommerce - a managed e-commerce hosting platform running 180+ high-profile online shops on Shopware, OXID eShop, Magento and other PHP based frameworks.

What we've seen

SQL injections in custom modules
Unrestricted file uploads in forgotten plugins
SSRF through proxy scripts
Legitimate code wrongly flagged by generic scanners

What we built into sec-scan

Deep understanding of OXID and Shopware internals
Standard ORM patterns recognized, not flagged
Catches the subtle issues that actually lead to breaches
Years of real-world attack patterns baked in

Frequently asked questions

Stop cleaning up hacks. Start preventing them.

Limited to 50 early access spots. Secure yours.