Ross ROSS = Recommend OSS · open-source software intelligence for agents

vigolium/vigolium

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision observed · 2026-09-01

github.com/vigolium/vigolium · homepage · Go · NOASSERTION (other) observed · 2026-09-01

Health v2 · maintenance only

82/100

  • Activity 100
  • Release rhythm 100
  • Longevity 12

Flags: young no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 2
  • age_days: 178
  • days_rel: 3
  • days_push: 3
  • n_releases_24m: 28

Full methodology

Adoption not part of the score

1055 stars · 155 forks observed · 2026-09-01

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for content discovery, spidering, and active/passive audits) with agentic AI-driven analysis that autonomously plans attacks and validates findings with proof. It ships as a CLI with an optional self-hosted Workbench dashboard and a cloud Console.

Use cases

  • scan web apps for injection and access control vulnerabilities
  • run a dast scanner in ci pipeline
  • audit an entire codebase for security bugs with ai
  • find vulnerabilities for bug bounty recon
  • detect blind out-of-band vulnerabilities
  • generate validated proof-of-concept findings instead of false positives

When to choose

  • you need fast deterministic dast scanning plus deeper ai-driven codebase audit in one tool
  • you want validated findings with evidence rather than noisy scanner output
  • you do bug bounty or penetration testing and want modular, scriptable scanning

When to avoid

  • you only need simple dependency or sast scanning without live-app testing
  • you require a permissive osi license - the license is non-standard
  • you cannot send code or traffic to ai-driven agentic scanning

Facets

cli-tool · maturity active

vulnerability-scanning security agent-framework cli web-scraping security penetration-testing web-development developer-tools artificial-intelligence windows cli go dast bug-bounty agentic-ai oast fuzzing source-code-audit self-hosted-dashboard linux macos docker nodejs

5 sources

Member repositories

RepositoryRoleHealth v2
vigolium/vigoliummain82

For agents

markdown · JSON · MCP: product_card(name="vigolium/vigolium")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem