Introducing VulnClarify: An Open-Source, AI-Enhanced Web Vulnerability Scanner for Small Organizations and Charities
In today’s digital landscape, cybersecurity remains a critical concern for small businesses, non-profits, and community organizations. Recognizing this gap, I’m thrilled to unveil my final university project — VulnClarify, an innovative proof-of-concept designed to simplify web security assessments through cutting-edge artificial intelligence technology.
What is VulnClarify?
VulnClarify is an early-stage tool that leverages the power of large language models (LLMs) to assist in identifying and understanding web application vulnerabilities. Built with accessibility in mind, it can be operated locally or within a Docker container, making it suitable for organizations without extensive technical resources.
Core Features:
- AI-Assisted Vulnerability Identification: Utilizes advanced language models to flag potential security issues and provide contextual explanations.
- User-Friendly Deployment: Designed for straightforward setup with Docker images, eliminating complex configurations.
- Educational and Exploratory: Serves as a foundational prototype to showcase how AI can augment cybersecurity assessments.
Motivation Behind the Project
Traditional vulnerability scanners are often costly and require specialized knowledge to interpret results effectively. My goal was to explore how artificial intelligence could lower these barriers, empowering smaller entities to proactively assess their web security and foster greater awareness without hefty investments.
How You Can Contribute
- Test the Tool: Use our pre-built Docker image for quick and hassle-free experimentation.
- Share Your Feedback: We welcome insights on usability, detection effectiveness, and potential improvements.
- Collaborate: Contribute code, fix bugs, or suggest new functionalities via GitHub pull requests.
- Expand Possibilities: Propose additional use cases or integrations where AI can enhance security tools.
Please Keep in Mind
- As a proof-of-concept, VulnClarify is still in development; expect some bugs or incomplete features.
- Conduct testing only on websites you own or have explicit permission to analyze.
- Refer to the project repository on GitHub for detailed instructions, disclaimers, and licensing information.
I am eager to discuss the project further, explore ideas around AI in cybersecurity, or hear how open-source initiatives can benefit smaller organizations. Your feedback and collaboration are invaluable as we push the boundaries of accessible digital security.
Thank you for your interest, and I look forward to engaging with the community!

