Skip to main content

redveil

web vulnerability scanner. find vulns, validate safely, get a report you can actually send to a dev team.


⚠️ DANGER ZONE — DWYOR (Do With Your Own Risk)

READ THIS BEFORE USING REDVEIL.

Redveil is intended for authorized security testing only.

  • ✅ You own the system, OR
  • ✅ You have explicit written permission to test it

If neither applies: DO NOT USE THIS TOOL.

The authors are not responsible for misuse, damage, data loss, or unauthorized activity resulting from the use of this software.

You are responsible for legal and ethical compliance.

See DWYOR.md for the full statement.


⚠️ Installation requires a virtual environment or pipx.

Modern Linux distros (Debian 12+, Ubuntu 23.04+, Fedora, etc.) enforce PEP 668 and block system-wide pip install with the error error: externally-managed-environment. Use one of these:

# Option 1: pipx (recommended, installs to isolated env, command globally available)
pipx install redveil-ui

# Option 2: python venv
python3 -m venv ~/redveil-env && source ~/redveil-env/bin/activate
pip install redveil-ui

See USER_GUIDE.md#install for distro-specific commands (apt, dnf, pacman, zypper, brew, etc.).

PyPI version Python versions License: MIT Tests Code style: ruff Security: tiered gate Negative testing Audit log

$ pip install redveil
$ redveil scan https://target.example --scope scope.yaml
$ redveil list-checks

Install

Recommended: pipx (PEP 668 compliant)

pipx install redveil-ui
pipx ensurepath
redveil-ui init
redveil-ui start

Modern Linux distros (Debian 12+, Ubuntu 23.04+, Fedora 38+) block bare pip install with the externally-managed-environment error (PEP 668). pipx installs each tool in its own venv — no system Python pollution.

Alternative: python -m venv

python3 -m venv ~/.redveil-ui-venv
source ~/.redveil-ui-venv/bin/activate
pip install redveil-ui
redveil-ui init
redveil-ui start

quick start

# 1. write a scope file
cat > scope.yaml <<'EOF'
target:
  base_url: https://staging.example.com
scope:
  allowed_hosts:
    - staging.example.com
  allowed_paths:
    - /api/*
    - /account/*
limits:
  requests_per_second: 2
  max_requests: 500
authorization:
  active_testing: false
  acknowledged_safety_terms: false
profile: passive
EOF

# 2. scan
redveil scan https://staging.example.com --scope scope.yaml

# 3. results
ls reports/staging.example.com/
cat reports/staging.example.com/summary.md
open reports/staging.example.com/report.html

what you get

  • 17 built-in checks — security headers, CORS, info disclosure, HTTP methods, open redirect indicators, source map exposure, XSS (canary reflection), SQLi (time-based), SSRF (OOB), command injection (time-based), path traversal (canary), BOLA/IDOR, BFLA, GraphQL, mass assignment, session/cookie config, subdomain discovery
  • multi-format reports — markdown per finding, JSON for tooling, self-contained HTML
  • strict scope enforcement — host + path allowlist, redirect chain validation, destructive path heuristic. plugins cannot bypass it
  • multi-principal auth for BOLA testing — define Account A + Account B in scope, redveil compares what each can see
  • evidence sanitization — JWTs, AWS keys, GitHub tokens, credit cards, cookies, emails all redacted before report
  • local lab at tests/lab/ — a Flask app with 17 deliberately vulnerable endpoints for testing without hitting the internet

safety

redveil is a defensive tool. the active checks (XSS, SQLi, SSRF, command injection, path traversal) use bounded non-destructive payloads:

  • XSS: alphanumeric canary strings. no <script>, no execution
  • SQLi/command injection: time-based delay only (sleep 3). no data extraction
  • SSRF: OOB callback to operator's own domain. no internal IP probing
  • path traversal: unique canary filenames. no real file reads

runtime assertions in each check verify these constraints on every import. the test suite has explicit safety tests for every check.

you are responsible for authorization. redveil includes guards but they only matter if you actually have permission to test the target.

see SECURITY.md for the full safety model and how to report issues.

CLI

$ redveil --help                # show all commands
$ redveil scan --help            # scan command flags
$ redveil check --help           # single-check flags
$ redveil list-checks            # list 17 registered check plugins
$ redveil findings <dir>         # show summary of a saved report
$ redveil report <dir>           # re-render a report

redveil scan <url>

Run a full scan against a target. Flags:

Flag Description
<url> Required. Target base URL, e.g. https://staging.example.com
-s, --scope FILE Path to a scope YAML file. If omitted, a minimal single-host scope is built.
-p, --profile PROFILE Safety profile: passive (default), low_impact, or active
--max-requests N Hard cap on total requests (default 500)
--rps N Requests per second (default 2.0)
--active Enable ACTIVE checks. Requires acknowledged_safety_terms: true in scope.
-g, --gate-mode MODE ActionGate mode: interactive, non_interactive (default), strict
--allow-destructive Explicit opt-in to unlock destructive actions (each still needs per-action typed confirm)
--max-destructive-level L Operator's ceiling. Short form L1-L6 or integer. Default 2 (data_modification).
-o, --output DIR Output directory for reports (default reports/)

redveil check <plugin-id> <url>

Run a single check plugin. Useful for targeted testing.

redveil check cors-policy https://staging.example.com
redveil check xss-reflected https://target.com --scope scope.yaml

redveil list-checks

List all 17 registered check plugins with their safety profile:

bfla                BFLA / Function-Level Authorization Check
bola-idor           BOLA / IDOR Check
command-injection    Command Injection Check (Time-Based)
cors-policy         CORS Policy Check
graphql             GraphQL Check
http-methods        HTTP Methods Check
information-disclosure  Information Disclosure Check
mass-assignment     Mass Assignment Check
open-redirect-indicator  Open Redirect Indicator
path-traversal      Path Traversal Check
security-headers    Security Headers Check
session-cookie      Session and Cookie Configuration Check
source-map-exposure Source Map Exposure Check
sqli-time-based     Time-Based Blind SQL Injection Check
ssrf                Server-Side Request Forgery Check
subdomain-finder    Subdomain Finder
xss-reflected       Reflected XSS Check

redveil findings <report-dir>

Print a summary of a previously-saved report.

redveil findings reports/staging.example.com/
# Output:
#   12 findings
#   - [HIGH    ] Missing X-Frame-Options Header
#   - [MEDIUM  ] Missing Content-Security-Policy Header
#   ...

redveil report <report-dir>

Re-render a report from existing findings.json (in case you want to regenerate the markdown/HTML after editing the JSON).

Safety profiles

  • passive (default) — only observation, no payload injection
  • low_impact — safe probes (CORS preflight, method check, harmless reflection)
  • active — requires active_testing: true in scope. Issues canary payloads, time-based delays, OOB callbacks, etc.

writing checks

a check is a Check subclass:

from redveil.plugins.base import Check, CheckCategory, CheckMeta, ...

class MyCheck(Check):
    meta = CheckMeta(
        id="my-check",
        name="My Check",
        category=CheckCategory.HEADERS,
        safety_profile=SafetyProfile.PASSIVE,
    )
    async def discover(self, ctx): ...
    async def validate(self, ctx, candidate): ...
    async def collect_evidence(self, candidate): ...
    async def assess(self, candidate): ...

register in pyproject.toml:

[project.entry-points."redveil.checks"]
my-check = "my_pkg.checks:MyCheck"

see CONTRIBUTING.md for the full plugin spec.

files

  • USER_GUIDE.md — installation, configuration, CLI reference, output interpretation
  • CONTRIBUTING.md — how to add checks
  • PUBLISH.md — how to publish a new release
  • SECURITY.md — safety model, how to report issues
  • CHANGELOG.md — release notes
  • docs/architecture.md — internal design
  • examples/ — scope files for common scenarios
  • tests/lab/ — vulnerable Flask app for local testing

status

17 checks, ~1090 tests passing, 0 known safety violations. actively used against staging environments. the framework ships with curated, tested-safe payloads; destructive actions require per-action typed confirmation (no batch approval) and an explicit allow_destructive: true unlock in config.

what makes redveil different from sqlmap / nikto / burp scanner

Aspect traditional scanner redveil
Payload signature match (e.g. ' OR 1=1 --) time-based delay, OOB callback, canary reflection
Action match pattern → flag model target → hypothesis → controlled test → multi-signal correlation → confidence-scored finding
Confidence hardcoded HIGH or LOW computed: oracle × (1 + log2(distinct_dims)) × weight − env_penalty − uncertainty
Reproducibility not verified ReplayRecipe + ReplayEngine runs N samples
FP reduction none negative testing, flakiness detection, env awareness, uncertainty propagation
Destructive implicit (run anyway) blocked by default. tiered confirmation L1-L6. no Y-to-all.

see USER_GUIDE.md and docs/architecture.md for details.

license

MIT. see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

redveil_ui-0.1.0.tar.gz (95.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

redveil_ui-0.1.0-py3-none-any.whl (756.2 kB view details)

Uploaded Python 3

File details

Details for the file redveil_ui-0.1.0.tar.gz.

File metadata

  • Download URL: redveil_ui-0.1.0.tar.gz
  • Upload date:
  • Size: 95.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.5

File hashes

Hashes for redveil_ui-0.1.0.tar.gz
Algorithm Hash digest
SHA256 99a92b7859521e31aadb4d58b164a0bb0f8c2b3641f70a7e710b6f20dccbbe2a
MD5 a83cb1ddfb6f29cd8a1e617d0a3bc7d9
BLAKE2b-256 618fdbbc03125ab1a95104a92b0208e4f6780e754f83e57002f57243064edabb

See more details on using hashes here.

File details

Details for the file redveil_ui-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: redveil_ui-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 756.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.5

File hashes

Hashes for redveil_ui-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 25bf580b16379592e21252a6d2489c535a160c750e2ea4262b79d8e8b21d9795
MD5 62a70a9b7fb6ec8d3890049fba66d7fb
BLAKE2b-256 b4bf1206f623743a8786af4c5daac2ddc9508873e302d42f5a1c92c5f10f3710

See more details on using hashes here.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.0

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

1 file

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page