Skip to main content
Glama

ScanPay โ€” Code Security Scanner with x402 v2 Micropayments

npm version npm downloads GitHub License: MIT

Deterministic AST-based security scanning for Python and JavaScript/TypeScript. No code execution. No AI inference. Just fast, reliable vulnerability detection. Pay per scan with Solana micropayments โ€” $0.10/scan.

๐ŸŽฏ What It Does

ScanPay analyzes source code for security vulnerabilities using deterministic AST parsing. No AI, no code execution โ€” just fast, reliable pattern matching that catches 45+ vulnerability classes before code runs.

Built for AI agents that generate code: scan before execution, block dangerous patterns, log audit trails.

Related MCP server: SAST MCP Server

โœจ Features

  • 45+ vulnerability patterns across Python and JS/TS/TSX

  • Deterministic analysis โ€” same input always produces same output

  • x402 v2 payment protocol โ€” pay per scan with SOL on Solana

  • Dual language support โ€” Python (ast module) and JS/TS (tree-sitter)

  • No false AI hallucinations โ€” pure rule-based detection

  • FastAPI-powered โ€” sub-100ms scan latency

  • SARIF output โ€” industry-standard vulnerability report format

  • Batch scanning โ€” scan multiple files in one request

๐Ÿš€ Quick Start

Using the Live API (testnet)

# Health check
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/health

# List available products
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/products

# Scan code (requires payment)
curl -X POST https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/scan \
  -H "Content-Type: application/json" \
  -d '{"source_code":"eval(userInput)","language":"python"}'
# โ†’ 402 Payment Required (0.0007 SOL)

Self-Host

git clone https://github.com/Misterio070/scanpay.git
cd scanpay
pip install -r requirements.txt
python main.py
# โ†’ http://localhost:8484

๐Ÿ’ณ Payment Flow (x402 v2)

  1. Client requests scan โ†’ receives 402 Payment Required

  2. Client pays 0.0007 SOL (~$0.10) to merchant wallet via Solana

  3. Client retries with X-PAYMENT header containing payment proof

  4. Server verifies payment on-chain, runs scan, returns results

Merchant wallet: JDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4

๐Ÿค– For AI Agents (MCP Server)

ScanPay includes an MCP server for AI agents to scan code before execution:

{
  "mcpServers": {
    "scanpay": {
      "command": "npx",
      "args": ["-y", "scanpay-cli", "scanpay-mcp"],
      "env": { "SCANPAY_URL": "https://repository-nil-camcorder-divx.trycloudflare.com" }
    }
  }
}

Agents call scan_code to check code for vulnerabilities before running it. Network: Solana testnet (mainnet coming soon)

๐Ÿ“‹ Configuration

cp .env.example .env

Env Var

Default

Description

SCANPAY_PAYMENT_MODE

disabled

disabled, testnet, or mainnet

SCANPAY_MERCHANT_WALLET

โ€”

Solana wallet address

SCANPAY_PRICE_LAMPORTS

700000

Price in lamports (0.0007 SOL)

SCANPAY_RPC_URL

https://api.devnet.solana.com

Solana RPC endpoint

SCANPAY_PORT

8484

Server port

๐Ÿงช Detected Vulnerabilities

Python

  • eval() / exec() โ€” code injection

  • subprocess with shell=True โ€” command injection

  • pickle.loads() โ€” deserialization attacks

  • os.system() โ€” command injection

  • SQL injection patterns

  • Path traversal (../)

  • Hardcoded credentials

  • And more...

JavaScript/TypeScript

  • eval() โ€” code injection

  • innerHTML โ€” XSS

  • document.write() โ€” XSS

  • new Function() โ€” code injection

  • SQL injection patterns

  • Prototype pollution

  • And more...

๐Ÿ“Š API Reference

GET /api/v1/health

Returns service status and configuration.

GET /api/v1/products

Returns available scan products and pricing.

POST /api/v1/scan

Scans source code for vulnerabilities. Requires payment in testnet/mainnet mode.

Request:

{
  "source_code": "eval(userInput)",
  "language": "python"
}

Response (200):

{
  "status": "ok",
  "findings": [
    {
      "rule": "PY001",
      "severity": "critical",
      "message": "Use of eval() detected โ€” code injection risk",
      "line": 1
    }
  ],
  "summary": {
    "total": 1,
    "critical": 1,
    "high": 0,
    "medium": 0,
    "low": 0
  }
}

๐Ÿค Built For

  • AI Agents โ€” scan generated code before execution

  • CI/CD Pipelines โ€” pre-deployment security gate

  • IDE Extensions โ€” real-time vulnerability detection

  • Code Review โ€” automated security audit

๐Ÿ“„ License

MIT

F
license - not found
-
quality - not tested
A
maintenance

Maintenance

โ€“Maintainers
โ€“Response time
โ€“Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

  • Solana token safety for AI agents โ€” rug-pull, honeypot & Token-2022 trap detection before you buy.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Misterio070/scanpay'

If you have feedback or need assistance with the MCP directory API, please join our Discord server