Skip to main content
Vigolium continuously scans popular open-source projects to validate detection coverage and demonstrate real-world results. These showcases are generated using Vigolium’s full scanning pipeline, native modules, agentic analysis (swarm + autopilot), and vigolium-audit whitebox security audits, against publicly available codebases.

Showcase Dashboard

Browse all scan results at demo.vigolium.com/showcases.
Open-source audit project list

Project list with severity breakdown per repository

Open-source audit findings detail

Detailed findings view for an individual project

Aggregate Results

What Gets Scanned

Each project goes through multiple scanning phases:

How to Read the Reports

Each showcase report includes:
  • Severity rating: Critical, High, Medium, or Informational
  • Vulnerability type: Mapped to CWE identifiers where applicable
  • Affected endpoint or code path: With request/response evidence for DAST findings and file/line references for SAST findings
  • Confidence level: Based on detection method (strict match, heuristic, or AI-assisted)
Findings are from automated scans against public repositories. Some results may be informational or context-dependent. Always verify findings before acting on them.