Ross ROSS = Recommend OSS · open-source software intelligence for agents

codingo/VHostScan

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages. observed · 2026-08-28

github.com/codingo/VHostScan · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

39/100

  • Activity 37
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3286
  • days_rel: n/a
  • days_push: 380
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1309 stars · 238 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-all/wildcard detection. It supports pivoting through SSH/nc, WAF-bypass headers, and HTTP/HTTPS scanning.

Use cases

  • discover hidden virtual hosts on a web server
  • find vhosts behind a catch-all wildcard response
  • enumerate subdomains via reverse lookups during a pentest
  • scan for virtual hosts through an SSH pivot
  • bypass WAFs while scanning vhosts
  • prepare for OSCP or HackTheBox recon

When to choose

  • you need vhost discovery that handles catch-all and dynamic default pages
  • you want a lightweight Python CLI for web app recon
  • you're pivoting through ssh/nc and need correct Host headers

When to avoid

  • you need full subdomain enumeration with DNS brute-forcing across nameservers
  • you want a GUI or automated web vulnerability scanner
  • the target is not a web server with virtual hosting

Facets

cli-tool · maturity active

security penetration-testing web-scraping http-client security penetration-testing web-development developer-tools windows python cli vhost-scanner virtual-hosts recon bugbounty ctf-tools offensive-security reverse-lookup wordlists linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
codingo/VHostScanmain39

For agents

markdown · JSON · MCP: product_card(name="codingo/VHostScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem