What are scanner engines?
ZeroFlaw uses multiple specialized security scanners simultaneously to find as many vulnerabilities as possible. Each engine specializes in certain programming languages or checks. Results are merged so you get a unified view.
Why multiple engines?
No single scanner finds everything. Different tools have different strengths:
- Some are better at SQL injection, others at XSS.
- Some analyze code flow (taint analysis), others search for patterns.
- Specialized tools check dependencies for known vulnerabilities (CVEs).
By combining multiple engines, ZeroFlaw significantly increases the detection rate.
Types of engines
SAST – Static Application Security Testing
SAST engines read your source code without executing it and look for:
- SQL injection, XSS, command injection
- Insecure cryptography
- Hardcoded passwords and credentials
- Insecure file operations
- Missing input validation
SCA – Software Composition Analysis
SCA checks your dependencies (libraries, packages). If you're using an npm package that has a known vulnerability, it will be flagged. Files like package.json, composer.json, requirements.txt or go.mod are analyzed.
Secret detection
These engines search for accidentally committed secrets:
- API keys (AWS, Google, Stripe etc.)
- Database passwords
- Private SSH keys
- OAuth tokens
Domain scanners
For domain scans, specialized engines check your website's infrastructure from the outside (see Domain scan).
AI-assisted analysis
In addition to rule-based engines, ZeroFlaw uses AI (Claude) to analyze results and provide better explanations. The AI helps to:
- Describe findings in plain language
- Reduce false positives
- Assess severity accurately
Engine selection
You don't need to select engines manually. ZeroFlaw automatically detects the programming languages in your project and starts the appropriate scanners. For domain scans all relevant checks are performed automatically.