One price per product, everything in.
Free finds and fixes on one repository at a time, in every language. Pro shows how the application will be attacked, reviews what changed, gates the release, writes the evidence, and audits the live Salesforce org. No tiers inside Pro, no add-ons, no per-module pricing.
Free
$0
Free, one repository at a time, no account. Never expires.
Find and fix, on one repository at a time, in every language. No account, and nothing to renew.
One line installs it. No sign-up wall.
- Scan. Find and fix on one repository at a time, in every language.
- Finding proof. Severity, disposition and the data-flow hops behind every finding.
- Fix. The deterministic fix and the AI fix.
- Packages and CVEs. Dependency CVEs with a reachability tag on each.
- Vulnerability data. The CVE bundle stays current on Free, air-gapped installs included.
- Local console. The console on this machine, on the active repository.
Pro
$200
$200 per seat per year, per product. Vulkro and Vulkro for Salesforce together: $400 per seat per year.
See how the application will be attacked, review what changed, ship, prove it to someone else, and operate at scale. Everything in Free is included.
Licences are issued directly by our team at license@vulkro.com. Fixed term, no auto-renewal. Start with a 14-day trial of the full product: sign in once from the scanner.
- Attack paths. Every entry point to every sink, across the whole application.
- Working-tree review. Review only what changed, with new findings separated from existing ones.
- Release gate. Fail a build on new findings, with the exit-code contract and the baseline diff.
- Pull-request output. Findings as review comments and CI annotations.
- Evidence formats. SBOM, VEX, CBOM, RoPA, PDF, CSV and JUnit output.
- Portfolio. Every repository at once, rolled up.
- Live-org audit. Permissions, session, MFA, sharing, packages and trust, read from the org itself.
A few free looks: each Pro view in the console and the editor opens three times on Free before it locks, so you can see what Pro adds on your own code before deciding anything.
Everything in Free and Pro, by surface.
The same words the command line, both consoles and both editor extensions use, generated from the list compiled into the scanner. A capability that runs in several places is listed once, under the place it belongs to, with every place it runs in the last column.
A finding is never shown with its proof hidden. Severity, the proven, unproven or not-checked disposition, the data-flow hops behind a finding, and explain and prove on one finding are all Free. The line is between the proof behind one finding, which is Free, and the map of the whole application, which is Pro.
Vulnerability data never goes stale on Free. The CVE bundle updates on the same schedule as Pro, air-gapped bundle installs included. What Pro sells is depth and operation, not data freshness.
The command line
Where the scan runs, and every command that reads its result.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Scanscan | Find and fix on one repository at a time, in every language | Command line, Console, Editor, AI assistants (MCP), Language server | Free |
| Finding prooffinding-proof | Severity, disposition and the data-flow hops behind every finding | Command line, Console, Editor, AI assistants (MCP) | Free |
| Prove and explainprove-explain | The evidence behind one finding, and what it means | Command line, Console, Editor, AI assistants (MCP) | Free |
| Route inventorydiscover | Every endpoint the project exposes, with its auth tier | Command line, Console | Free |
| Packages and CVEspackages | Dependency CVEs with a reachability tag on each | Command line, Console, Editor | Free |
| Secrets in the working treesecrets-working-tree | Credentials committed in the files on disk | Command line, Console, Editor | Free |
| Vulnerability datacve-data | The CVE bundle stays current on Free, air-gapped installs included | Command line, Console | Free |
| Supply-chain vettingsupply-chain-vetting | Vet an MCP server, an extension or a dependency before it lands | Command line, Console, AI assistants (MCP) | Free |
| Secrets in git historygit-history-secrets | Credentials that were committed and then removed | Command line, Console | Pro |
| Inferred OpenAPI specopenapi | The API contract inferred from the code, with a score | Command line, Console | Pro |
| RBAC matrixrbac | Every endpoint against every auth tier, in one table | Command line, Console | Pro |
| API-surface diffapi-diff | What the API contract gained and lost between two refs | Command line, Console | Pro |
| Respondrespond | The incident-response workflow over a finding | Command line, Console | Pro |
| Runtime probeprobe | Confirm a finding against the running application | Command line, Console | Pro |
| Container scanningcontainer | Scan the image the service ships in | Command line, Console | Pro |
| Deep presetdeep-preset | Every confidence tier, unreachable code included, no evidence floor | Command line | Pro |
| Strict confidencestrict-confidence | Drop High findings that carry an empty evidence bag | Command line | Pro |
| Verified tierverified-tier | Promote a finding to verified when the proof clears the bar | Command line | Pro |
| Opt-in detector packsdetector-packs | Business logic, money handling, state machines and concurrency | Command line | Pro |
| Rule-pack importcustom-rules | Bring an external or private rule pack into the engine | Command line | Pro |
The console
The local web console on your machine, and the views that turn one scan into a picture of the whole application.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Local consoleconsole-local | The console on this machine, on the active repository | Command line, Console | Free |
| Baseline, suppressions and triagebaseline-triage | Accept what you have and track what is new | Command line, Console, Editor | Free |
| Attack pathsattack-paths | Every entry point to every sink, across the whole application | Console, Editor | Pro |
| Impactimpact | What a finding reaches, scored, with the exposed endpoints per module | Console, Editor | Pro |
| Data-flow mapdataflow-map | Every source-to-sink flow in the project, as one map | Command line, Console, Editor | Pro |
| Code-structure mapcode-structure | Modules, calls and layering as one map | Command line, Console, Editor | Pro |
| Scan historyhistory | Every scan this project has run, kept and comparable | Command line, Console, Editor | Pro |
| Trendstrends | How the risk moved between scans | Command line, Console, Editor | Pro |
| Compare scanscompare | Two scans side by side, with what changed named | Console, Editor | Pro |
| Hotspots and contributorshotspots | Which files and which people the risk follows | Command line, Console | Pro |
| Portfolioportfolio | Every repository at once, rolled up | Command line, Console | Pro |
| Shared consoleteam-console | One console the team reads, on a network bind | Command line, Console | Pro |
The editor
The Vulkro extension for VS Code, Cursor, Windsurf and VSCodium. Everything above that lists the editor as a place it runs is in the extension too.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Fixfix | The deterministic fix and the AI fix | Command line, Console, Editor, AI assistants (MCP) | Free |
| Working-tree reviewchanges | Review only what changed, with new findings separated from existing ones | Command line, Console, Editor, AI assistants (MCP) | Pro |
AI assistants and MCP
The skill, the guard hook and the MCP server for Claude Code, Cursor, Codex and the assistants that speak MCP.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| AI recommendationsai-assist | Ask, hunt, explain and triage with a model you choose | Command line, Console, Editor, AI assistants (MCP) | Free |
| Guard hookguard | Block insecure code before it is written | Command line, Editor, AI assistants (MCP) | Free |
| AI impact narrativeai-impact-narrative | The impact graph, explained in prose | Console, Editor | Pro |
The pipeline
What runs in CI. A severity exit policy is Free: the default preset uses it. The diff-scoped gate and the pull-request output are Pro.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Release gaterelease-gate | Fail a build on new findings, with the exit-code contract and the baseline diff | Command line | Pro |
| Pull-request outputpr-comments | Findings as review comments and CI annotations | Command line | Pro |
| Notifynotify | Slack, Teams and webhook delivery | Command line, Console | Pro |
Evidence
What you hand to someone else: an auditor, a customer, a regulator.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Evidence formatsevidence-formats | SBOM, VEX, CBOM, RoPA, PDF, CSV and JUnit output | Command line, Console, Editor | Pro |
| Executive reportreport | The PDF and HTML report you hand to someone else | Command line, Console, Editor | Pro |
| Compliance evaluatorcompliance | Findings mapped to the control they break | Command line, Console | Pro |
| Compliance packcompliance-pack | The audit-evidence bundle, per framework | Command line, Console | Pro |
| SBOMsbom | The bill of materials, in every format an auditor asks for | Command line, Console | Pro |
| SBOM CVE matchingmatch-cve | Match an external SBOM against the offline CVE bundle | Command line, Console | Pro |
Salesforce: Vulkro for Salesforce
Vulkro for Salesforce is licensed on its own. Free scans the project and shows the readiness checklist on screen; Pro audits the live org and writes the report you hand over.
| Capability | What it is | Where it runs | Tier |
|---|---|---|---|
| Salesforce scansf-scan | Apex, LWC, Aura, Visualforce, Flow and metadata on one project | Command line, Console, Editor, AI assistants (MCP), Language server | Free |
| Readiness checklistsf-readiness | Where the package stands against the Security Review, on screen | Command line, Console | Free |
| Attack surfacesf-explore | What is externally reachable, and what a guest user can hit | Command line, Console | Free |
| Project referencesf-reference | Docs, consistency checks, the rule playbook and package CVEs | Command line, Console | Free |
| Live-org auditsf-live-org | Permissions, session, MFA, sharing, packages and trust, read from the org itself | Command line, Console, AI assistants (MCP) | Pro |
| Guest exposuresf-exposure | What an unauthenticated visitor reaches in the org | Command line, Console | Pro |
| Presubmit gatesf-presubmit | Fail the build before the package is submitted | Command line | Pro |
| AppExchange reportsf-appexchange-report | The readiness report you hand to the Security Review team | Command line, Console | Pro |
| Salesforce compliancesf-compliance | The evidence pack, rendered and bundled | Command line, Console | Pro |
| Blast radiussf-impact | What a change touches, before it ships | Command line, Console, Editor | Pro |
| Org mapssf-maps | Flows, roles and where the PII lives, as maps | Command line, Console | Pro |
| Anti-patternssf-antipatterns | The Well-Architected review, run over the project | Command line, Console, AI assistants (MCP) | Pro |
| Salesforce trendssf-trends | How the org posture moved, with event monitoring | Command line, Console | Pro |
| Org-scale operationssf-org-scale | Recertification, limits, coverage risk and masking rules | Command line, Console | Pro |
| Salesforce portfoliosf-portfolio | Every client org at once, rolled up | Command line, Console | Pro |
| Secrets in git historysf-git-history-secrets | Credentials that were committed to this project and then removed | Command line, Console | Pro |
| PMD wrappersf-pmd-wrapper | Merge a local PMD-for-Apex run into the report | Command line | Pro |
| ESLint wrappersf-eslint-wrapper | Merge a local ESLint run over LWC and Aura into the report | Command line | Pro |
| RetireJS wrappersf-retirejs-wrapper | Flag vulnerable JavaScript vendored into static resources | Command line | Pro |
The id under each capability is the one the scanner prints when it refuses a Pro feature on Free, so a refusal can be looked up here word for word. The scanner renders this same table with vulkro license-status --format markdown.
Two products, licensed on their own.
One review of the code you write, one review of what your team built on Salesforce. The same engine, the same words, two seats.
Vulkro, for the code buyer
Python, JavaScript, TypeScript, Go, Java, C, C++ and PHP, plus the containers, infrastructure files and package lists next to the code, on your own machine. Free finds every vulnerability on one repository at a time with the path that proves it. Pro adds the application-wide maps, the diff-scoped release gate, the evidence an auditor asks for, and every repository at once.
Vulkro for Salesforce, for the Salesforce buyer
Apex, Lightning, Aura, Visualforce, Flow and metadata, with unlimited orgs on one seat. Free scans the project and shows where the package stands against the Security Review, on screen. Pro reads the live org itself, permissions, session, MFA, sharing, packages and trust, writes the readiness report you hand to the Security Review team, and rolls every client org up at once.
Each product is licensed on its own. A Vulkro seat never unlocks a Salesforce capability, and a Vulkro for Salesforce seat never unlocks a code-scanner one. Both together on one seat: $400 per seat per year.
Air-gapped and site-wide teams.
A machine with no route out runs from a licence file bound to that machine and verified locally: no calls home, the vulnerability bundle carried in by hand, and Pro on the file's terms. Site-wide licences for a whole network are the same conversation. Write to license@vulkro.com and say which machines cannot reach the internet.
Questions people ask before they buy.
What happens after the trial?
The first verified device login starts a 14-day term of the full product. When it ends the machine returns to Free: scanning continues on one repository at a time, with every finding, its proof and the fix, and nothing you produced disappears. To keep Pro, write to license@vulkro.com or run the buy command in the scanner, and our team issues the seats.
What happens when Pro lapses?
Renewal reminders first, then a grace window, then the machine drops to Free and keeps scanning. The most recently scanned repository keeps working, and vulnerability data stays current. Nothing stops.
How do seats work?
One seat is one person. Seats are reassignable in the portal, so a seat follows the team, not the laptop. A seat is per product: a Vulkro seat never unlocks a Salesforce capability, and the reverse.
Who sends the invoice?
Invoices come from Reveriext Solutions LLP. Billing and invoice questions go to billing@vulkro.com.
Does it renew? Can I get a refund?
Every licence is issued for a fixed term and paid in advance. Nothing renews on its own and there is no recurring charge, so there is nothing to cancel. We do not offer refunds: once a licence is issued it cannot be revoked. The terms say the same.
I was using Vulkro before this page existed. What changes for me?
Nothing is taken away. A licence file you already hold keeps working as issued, on the machine it was bound to, until its expiry, and an account that was on the full product stays on it. Free no longer needs a sign-in, so a machine that used to be blocked when its term ended now keeps scanning instead.
Does my code ever leave the machine?
It does not. The scan, the findings and the proof stay on your machine. The only thing that goes out is a small anonymous usage heartbeat, and scan content is never part of it. With the air-gap switch on, nothing goes out at all. What the heartbeat carries, field by field.