Checked. Cited. Fixes drafted. Nothing applied without your approval.
Drop a scanner export and the fix engine's own parsers read it here, in your browser. Every finding is mapped to its OWASP Top 10 category, given the fix the engine can draft, and named the fix technique the engine has validated for its weakness class.
Your file is not uploaded. The page reads it here, in your browser. After it runs, the page sends us one short line: which scanner made the file, how many findings it had, and how many the engine could draft for. Nothing else — not the file, not a finding, not your name. You can watch that one request in your browser's developer tools.
Accepted: Trivy JSON · Grype JSON · ZAP JSON/XML · SARIF JSON · Snyk JSON · OSV-Scanner JSON · Nuclei JSON/JSONL · Burp XML · Qualys XML · Nessus XML. Files up to 25 MB and 20,000 findings.
This page ships with a Content-Security-Policy that allows exactly one network destination: our run counter. Your file stays on your machine.
Network requests since your file was read: 0 — the one allowed is the run-count line.
Real Trivy 0.72.0 scan of nginx:1.19.10 (nginx@sha256:df13abe416e37eb3db4722840dd479b00ba193ac6606e7902331dcea50f4f1f2) on 2026-09-15T17:47:02.380026577Z. Reproduce: docker run --rm aquasec/trivy:0.72.0 image --format json --output nginx-1.19.10.trivy.json nginx:1.19.10 Fields the page does not read (descriptions, references, CVSS vectors, timestamps) were removed to fit the page; every remaining value is the scanner's own, unchanged. The untouched report is identified by originalSha256.
0 of 0 findings have a drafted fix · 0 are in a validated weakness class · 0 not assessed
Drafts are from your scan's own data and the engine's rule table. Nothing here was validated on your code.
The engine drafts these from its rule table, each step cited. This is the engine's real output for your rule ids.
| Finding | Weakness | Fix |
|---|
The engine drafts these from the version pair in your scan. The fixed version is the one your scanner reported.
| Finding | Weakness | Fix |
|---|
The engine has validated a fix technique for this weakness class. Drafting it for your code happens inside the product, with your approval.
| Finding | Weakness | Fix |
|---|
No weakness id the engine can act on, or a category with no code fix. The engine does not draft from thin air.
| Finding | Weakness | Fix |
|---|
For the full engine run — cited fix steps for every finding, precedent data and a recorded validation — we run it for you. Ask, and we send a private, single-use report link.