KASCVE
A CVE scanner and security hardening tool that scans websites for known vulnerabilities and generates configuration patches
Library Rated 7 Oct 2026Dormant
- Built by
Tetstack
Bloat
115/500Where it landed on the scale
0
300
400
Summary
KASCVE is a working CLI with a public MIT repo and one release, shipped over about three weeks and then set aside. The creator calls it a failed project that was never finished, and the planned API, web, desktop and mobile apps never appeared. It has a real use but little moat, no payment path for the open version, and no sign it is still being worked on.
Bloat · Not much here works or looks likely to last, yet.
Breakdown
Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.
Viability
Is there a real problem, someone who would pay, and a market this builder can actually reach?
Scanning sites for known CVEs and giving ready-made config patches is a real problem. But the open-source tool has no pricing or payments, and the one stated sales idea (a separate bug-bounty edition) is a private DM offer with no price or buyer shown.
28/100
Rubric 21–40A real problem, but no plausible path to anyone paying, or a market well out of this builder's reach.
Receipts (3)
Describes a scanner that outputs exact Nginx, Apache and Laravel patches, which addresses a real need.
“The tool is officially done and the repository is live for everyone to access. Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments. KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, an”
Post · @Tetstack · 30 May 2026 · open on Telegram (opens in a new tab)
Says it will sell an advanced KASCVE-BUG version by DM, with no price, product page or buyer mentioned.
“I need some money so I will start selling advanced version of the KASCVE tool known as KASCVE-BUG for specifically bug-bounty. If any one want to buy my tool it's for sale just PM me”
Post · @Tetstack · 31 May 2026 · open on Telegram (opens in a new tab)
The creator calls KASCVE a failed project that was never finished.
“You accept failure in the gym because you know it's optimal for growth. Then why fear it everywhere else? KASCVE was one of my very many failed project i couldn't finished but in the way it taught me a lot stuff's. I had and will have fail in the future, your life will have failure when trying to build your life, or a code or anything.You were never perfect and you never will, you were created t”
Post · @Tetstack · 25 Jun 2026 · open on Telegram (opens in a new tab)
Moat
What stops someone copying it?
Version-matching against known CVEs plus fuzzing with SecLists is something others already do well and for free, and the builder says the logic is hard-coded. Nothing here is proprietary, compounding or locally specific.
12/100
Rubric 0–20A thin wrapper or a clone that anyone here could rebuild in a weekend.
Receipts (2)
Explains the detection as hard-coded matching of detected framework and server versions to CVEs, which is easy to copy.
“Thanks to @mr_mishaa1, I didn't relise KASCVE scanned soft 404 pages and returned them a vulnerability, I will edit that out and and the hard-coded logic for the way it searches is by identifying what your websites use like the frame work and server and the version then it will look for any CVE's that will be above that version even if you fixed the code I will include this on the app and not the ”
Post · @Tetstack · 1 Jun 2026 · open on Telegram (opens in a new tab)
The repo is an MIT-licensed tool built on public SecLists wordlists, so anyone can fork it.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/KASCVE (opens in a new tab)
Momentum
Did the updates keep coming?
Active for about 26 days from late May to late June 2026, with a release and a few commits, then nothing for over 100 days after the creator moved to another project.
0/100
- Sustained shipping0/60
Worked on across 26 days.
- Consistency0/40
Updates in 1 of 1 month.
- Quiet
No update for 104 days, so scaled to 48%.
Receipts (2)
Earliest post about it.
“The tool is officially done and the repository is live for everyone to access. Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments. KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, an”
Post · @Tetstack · 30 May 2026 · open on Telegram (opens in a new tab)
Most recent post about it.
“You accept failure in the gym because you know it's optimal for growth. Then why fear it everywhere else? KASCVE was one of my very many failed project i couldn't finished but in the way it taught me a lot stuff's. I had and will have fail in the future, your life will have failure when trying to build your life, or a code or anything.You were never perfect and you never will, you were created t”
Post · @Tetstack · 25 Jun 2026 · open on Telegram (opens in a new tab)
Infrastructure
Does a real, working product exist?
A working CLI scanner exists with a release, install script and plugin structure, though it had false-positive bugs and the planned API and web app never shipped.
54/100
- It's live20/20
https://github.com/PicasoTheDeal/KASCVE responded when checked.
- HTTPS5/5
Hosted on a platform (store, GitHub or Telegram), so HTTPS is the platform's.
- Real product25/35
A working CLI was released with install script, basic, advanced and deep scan modes, and a plugin structure. It had a known soft-404 false-positive bug, and the promised API, web app and dashboard were never delivered.
- Own home0/10
No home found.
- Maintained0/15
Last sign of shipping 2026-06-25.
- Operations4/15
There is a GitHub repo with documentation, an install script and one release. The backend API and web app were only planned, and there is no status page or accounts system.
Receipts (5)
https://github.com/PicasoTheDeal/KASCVE responded when checked.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/KASCVE (opens in a new tab)
Announces a finished tool with an install script and several scan tiers.
“The tool is officially done and the repository is live for everyone to access. Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments. KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, an”
Post · @Tetstack · 30 May 2026 · open on Telegram (opens in a new tab)
Admits it reported soft 404 pages as vulnerabilities, so accuracy was thin.
“Thanks to @mr_mishaa1, I didn't relise KASCVE scanned soft 404 pages and returned them a vulnerability, I will edit that out and and the hard-coded logic for the way it searches is by identifying what your websites use like the frame work and server and the version then it will look for any CVE's that will be above that version even if you fixed the code I will include this on the app and not the ”
Post · @Tetstack · 1 Jun 2026 · open on Telegram (opens in a new tab)
Tested the backend on a deliberately vulnerable site, which shows some real testing.
“So update on the KASCVE-PROJECT, i needed to test the back-end on a target so i had to create a full website with specific and intentional vulnerability but had to use bolt.new (ai), i am sorry i had too it's just for a test and not the real app so i made it with bolt.new had to tweak some stuff and then upload it on huggingface.co with a docker build and then setup the cloudflare on it, but i wil”
Post · @Tetstack · 18 Jun 2026 · open on Telegram (opens in a new tab)
Points to documentation and an automated setup script.
“The tool is officially done and the repository is live for everyone to access. Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments. KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, an”
Post · @Tetstack · 30 May 2026 · open on Telegram (opens in a new tab)
Sustainability
Is it being set up to last?
Distribution is only a GitHub release, with no payments, pricing, privacy or terms pages, or support contact beyond DMs. The creator has called it a failed project and moved on, so there is no sign of continued commitment.
21/100
- Distribution10/30
Versioned downloadable releases (1 on GitHub).
- Payments0/15
No payment provider found.
- Pricing0/10
No pricing found on the site.
- Revenue0/5
No customer or sale is mentioned. The only sales intent is an offer to sell a separate version by DM.
- Privacy policy0/7
No privacy policy found.
- Terms0/5
No terms of service found.
- Support8/8
Posts point users to a support channel.
- Commitment3/20
The builder posted regular updates for a few weeks and had a roadmap, but then paused the project for ZeroShadow and later called it a failure. There is no team, funding or dedicated project channel.
Receipts (5)
Versioned downloadable releases (1 on GitHub).
Checked 7 Oct 2026 · github.com/PicasoTheDeal/KASCVE (opens in a new tab)
Says the paid version is for sale but reports no buyer.
“I need some money so I will start selling advanced version of the KASCVE tool known as KASCVE-BUG for specifically bug-bounty. If any one want to buy my tool it's for sale just PM me”
Post · @Tetstack · 31 May 2026 · open on Telegram (opens in a new tab)
Sets KASCVE aside to start a different project.
“So guys basically i will be making a specific kind of project that i had in my mind i had the blueprint but never the time i will set KASCVE aside for a moment cuz i can't do it with this limitation. So this project is called ZeroShadow It's a a very small, low level security framework designed to protect compiled linux applications from memory corruption exploits specifically Return-Oriented ”
Post · @Tetstack · 19 Jun 2026 · open on Telegram (opens in a new tab)
Describes KASCVE as a failed, unfinished project.
“You accept failure in the gym because you know it's optimal for growth. Then why fear it everywhere else? KASCVE was one of my very many failed project i couldn't finished but in the way it taught me a lot stuff's. I had and will have fail in the future, your life will have failure when trying to build your life, or a code or anything.You were never perfect and you never will, you were created t”
Post · @Tetstack · 25 Jun 2026 · open on Telegram (opens in a new tab)
Lays out a roadmap that was not followed through.
“For anyone new here, here is what's being built. This project is a direct, full-scale advancement of the KASCVE-PROJECT. The goal is a unified, API-backed ecosystem: Web: Landing page done. Dashboard, scanning, history, and threat intel up next. Desktop: Native clients for Linux and Windows. Mobile: Android app. Backend: Full API system powering everything. Landing page is complete. Moving o”
Post · @Tetstack · 2 Jun 2026 · open on Telegram (opens in a new tab)