Developer Reference
Vulnerability Intelligence
DomScan API: Find exposed software, risky configurations, and known affected versions across a public website. Every result explains what was checked, why it matched, and how strong the evidence is.
Vulnerability Intelligence
Find exposed software, risky configurations, and known affected versions across a public website. Every result explains what was checked, why it matched, and how strong the evidence is.
GET
/v1/vulnerabilities
Query Parameters
| Parameter | Type | Description |
|---|---|---|
| url optional | string | Full public HTTP(S) URL to analyze. If both URL and domain are provided, URL takes precedence. |
| domain optional | string | Public domain or HTTP(S) URL to analyze. Provide either URL or domain. |
| mode optional | string standard | deep |
Scan mode: standard is the default and costs 8 credits, deep adds isolated JavaScript rendering and costs 12 credits. No other value is accepted. |
Advisory sources and coverage
Correlate verified public technology versions with authoritative package advisories, known exploitation, and exploit probability. DomScan keeps affected versions, security misconfigurations, and unknown coverage separate so teams can fix the strongest evidence first.
| Field | Description |
|---|---|
checked | The source was queried and the result is reflected in the findings. |
not_requested | There was nothing to ask the source. No detected component carried a version mapped to a reviewed package, so no advisory was queried and no CVE reached the exploitation sources. This is a coverage limit, not proof that the target is unaffected. |
partial / failed | The source was queried but answered incompletely or not at all. Affected components stay unknown and are never reported as safe. |
Example Request
curl -H "X-API-Key: your-api-key" "https://domscan.net/v1/vulnerabilities?domain=example.com&mode=standard" -H "x-api-key: YOUR_API_KEY"
import requests
domscan = requests.Session()
domscan.headers.update({"X-API-Key": "your-api-key"})
response = domscan.get(
"https://domscan.net/v1/vulnerabilities",
params={"domain": "example.com", "mode": "deep"},
headers={"x-api-key": "YOUR_API_KEY"},
)
result = response.json()
print(result["summary"]["posture"])
print(result["coverage"]["package_advisories"])
Response Fields
| Field | Type |
|---|---|
target |
object |
target.requested_url |
string |
target.final_url |
string |
target.hostname |
string |
scan |
object |
scan.mode |
string |
scan.status |
string |
scan.checked_at |
string |
scan.duration_ms |
integer |
scan.disclaimer |
string |
summary |
object |
summary.posture |
string |
summary.risk_level |
string |
summary.finding_count |
integer |
summary.version_affected_count |
integer |
summary.misconfiguration_count |
integer |
summary.urgent_count |
integer |
summary.severity_counts |
object |
findings[] |
object[] |
findings[] |
object |
findings[].fingerprint |
string |
findings[].classification |
string |
findings[].severity |
string |
findings[].priority |
string |
findings[].title |
string |
findings[].summary |
string |
findings[].component |
object |
findings[].component.technology_id |
string |
findings[].component.name |
string |
findings[].component.detected_version |
string |
findings[].component.version_kind |
string |
findings[].component.confidence |
string |
findings[].component.confidence_score |
integer |
findings[].component.ecosystem |
string |
findings[].component.package |
string |
findings[].component.purl |
string |
findings[].advisory |
object |
findings[].advisory.id |
string |
findings[].advisory.aliases[] |
string[] |
findings[].advisory.cves[] |
string[] |
findings[].advisory.published_at |
string | null |
findings[].advisory.modified_at |
string | null |
findings[].advisory.cvss[] |
object[] |
findings[].advisory.cvss[] |
object |
findings[].advisory.cvss[].type |
string |
findings[].advisory.cvss[].vector |
string |
findings[].advisory.fixed_versions[] |
string[] |
findings[].advisory.affected_ranges[] |
object[] |
findings[].advisory.affected_ranges[] |
object |
findings[].advisory.references[] |
string[] |
findings[].exploitation |
object |
findings[].exploitation.cisa_kev |
boolean | null |
findings[].exploitation.kev_added_at |
string | null |
findings[].exploitation.kev_required_action |
string | null |
findings[].exploitation.known_ransomware_use |
string | null |
findings[].exploitation.epss_probability |
number | null |
findings[].exploitation.epss_percentile |
number | null |
findings[].exploitation.epss_date |
string | null |
findings[].evidence |
object |
findings[].evidence.confidence |
string |
findings[].evidence.observed[] |
string[] |
findings[].evidence.limitations[] |
string[] |
findings[].remediation |
object |
findings[].remediation.summary |
string |
findings[].remediation.fixed_versions[] |
string[] |
findings[].sources[] |
string[] |
components[] |
object[] |
components[] |
object |
components[].technology_id |
string |
components[].name |
string |
components[].detected_version |
string | null |
components[].version_kind |
string | null |
components[].confidence |
string |
components[].advisory_status |
string |
components[].matched_advisories |
integer |
coverage |
object |
coverage.target_response |
string |
coverage.technology_detection |
string |
coverage.package_advisories |
string |
coverage.known_exploitation |
string |
coverage.exploitation_probability |
string |
coverage.detected_components |
integer |
coverage.versioned_components |
integer |
coverage.advisory_eligible_components |
integer |
coverage.advisory_checked_components |
integer |
coverage.advisory_deferred_components |
integer |
coverage.advisory_query_limit |
integer |
coverage.relay_used |
boolean |
coverage.limitations[] |
string[] |
sources[] |
object[] |
sources[] |
object |
sources[].id |
string |
sources[].name |
string |
sources[].owner |
string |
sources[].url |
string |
sources[].status |
string |
sources[].retrieved_at |
string | null |
sources[].cache_hit |
boolean |
sources[].expected_freshness |
string |
sources[].fallback_behavior |
string |
sources[].cost |
string |
_meta |
object |
Example Response
{
"target": {
"requested_url": "https://example.com",
"final_url": "https://example.com",
"hostname": "example.com"
},
"scan": {
"mode": "standard",
"status": "complete",
"checked_at": "2026-08-27T12:00:00Z",
"duration_ms": 1,
"disclaimer": "example"
},
"summary": {
"posture": "action_required",
"risk_level": "critical",
"finding_count": 1,
"version_affected_count": 1,
"misconfiguration_count": 1,
"urgent_count": 1,
"severity_counts": {}
},
"findings": [
{
"fingerprint": "example",
"classification": "version_affected",
"severity": "critical",
"priority": "urgent",
"title": "example",
"summary": "example",
"evidence": {
"confidence": "high",
"observed": [
"example"
],
"limitations": [
"example"
]
},
"remediation": {
"summary": "example",
"fixed_versions": [
"example"
]
},
"sources": [
"osv"
],
"component": {
"technology_id": "example",
"name": "example",
"detected_version": "example",
"version_kind": "product",
"confidence": "high",
"confidence_score": 85,
"ecosystem": "example",
"package": "example",
"purl": "https://example.com"
},
"advisory": {
"id": "example-id",
"aliases": [
"example"
],
"cves": [
"example"
],
"published_at": "2026-08-27T12:00:00Z",
"modified_at": "2026-08-27T12:00:00Z",
"cvss": [
{
"type": "domain",
"vector": "example"
}
],
"fixed_versions": [
"example"
],
"affected_ranges": [
{}
],
"references": [
"https://example.com"
]
},
"exploitation": {
"cisa_kev": false,
"kev_added_at": "2026-08-27",
"kev_required_action": "example",
"known_ransomware_use": "example",
"epss_probability": 0.85,
"epss_percentile": 0.5,
"epss_date": "2026-08-27"
}
}
],
"components": [
{
"technology_id": "example",
"name": "example",
"detected_version": "example",
"version_kind": "example",
"confidence": "high",
"advisory_status": "checked",
"matched_advisories": 1
}
],
"coverage": {
"target_response": "example",
"technology_detection": "example",
"package_advisories": "example",
"known_exploitation": "example",
"exploitation_probability": "example",
"detected_components": 1,
"versioned_components": 1,
"advisory_eligible_components": 1,
"advisory_checked_components": 1,
"advisory_deferred_components": 1,
"advisory_query_limit": 1,
"relay_used": false,
"limitations": [
"example"
]
},
"sources": [
{
"id": "example-id",
"name": "example",
"owner": "example",
"url": "https://example.com",
"status": "available",
"retrieved_at": "2026-08-27T12:00:00Z",
"cache_hit": false,
"expected_freshness": "example",
"fallback_behavior": "example",
"cost": "none"
}
],
"_meta": {}
}
Coverage and sources:
A clean result cannot prove that an application is vulnerability-free or replace an authorized penetration test.

