Product

Changelog

Last updated October 8, 2026

What changed in Vulnix, newest first. Changes to the API are recorded separately in the API changelog.

Stricter browser security in the dashboard

  • The dashboard now allows only scripts that carry a one-time key issued for each page load, so a script injected into a page does not run.
  • app.vulnix.dev opens straight to your dashboard, or to sign-in when you are signed out.

Vulnix now runs on Google Cloud in Frankfurt

  • The platform moved to Google Cloud in Frankfurt, Germany. Your data stays in the EU, as before.
  • Product analytics, which you can decline in the cookie banner, now go to PostHog's EU region.

Vulnix MCP: run pentests from your AI apps

  • Connect Claude, ChatGPT, Cursor or any MCP client to https://api.vulnix.dev/mcp and sign in with your Vulnix account.
  • Start and watch pentests, triage findings, check a fix and manage domains, scopes and knowledge in plain language.
  • You choose what each connection may do at sign-in. Actions that spend credits are never pre-selected, and owners and admins can turn AI apps off or cap their permissions.
  • Connections are listed and revocable under API, MCP.
  • A light and dark theme switch is now in the client and staff portals.

Chat reads Arabic and goes deeper on a finding

  • Arabic and other mixed-direction text now renders correctly in chat.
  • Ask the agent to go deeper on a finding and it treats that as real testing work, with the finding's detail and its log in front of it.

Self-contained finding reports

  • Each finding's report now carries the engine's full detail, so it can be read and shared on its own.

Test accounts, plans and a new top bar

  • A test account is checked as soon as you save it, and the evidence of the login attempt is kept with it.
  • A domain can hold up to three test users, and every test account needs a valid login URL.
  • Compare plans side by side and change your plan from one picker.
  • Your account menu, notifications and a link to the docs sit in a top bar on every page.

More ways to sign in, and to test behind a login

  • Sign in or sign up with Google first, with email and password one click away.
  • Give the agent a test account that signs in with Google, a username and password with a one-time code, or a magic link.
  • Connect GitHub and your DNS provider while you set up, without leaving onboarding.

The dashboard moves to app.vulnix.dev

  • Sign in at app.vulnix.dev. The website stays on vulnix.dev, and links to the old addresses redirect.
  • You were signed out once during the move.