Integrate Dradis with Vulnetix. Use the Dradis REST API to export issues and evidence from pentest projects, then upload to Vulnetix for centralised vulnerability management.
How Vulnetix compares: better together
Vulnetix does not replace Dradis. Keep running it. Vulnetix sits on top of Dradis (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Dradis is strongest at its core category and also carries features in Network & Vulnerability Scanners, DAST, SCA, just as Vulnetix spans categories.
| Capability | Vulnetix | Dradis |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Can ingest dependency findings from connected tools; no native SCA |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ~ Ingests Burp/Acunetix/ZAP web-scan findings |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ~ Imports Nessus/Nmap/Qualys/NeXpose network-scan output; runs no scanner itself |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✓ Core: consolidates manual + tool findings into a project workspace and generates reports |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Combine/replace/merge processing of findings across 47+ supported tools; manual-oriented, not a full ASPM dedup engine |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Dradis does well
- Pixel-perfect, template-driven pentest report generation that combines automated and manual findings in a few clicks
- 47+ out-of-the-box scanner connectors (Nessus, Burp, Nmap, Qualys, Acunetix, Metasploit, NeXpose) to import and normalize output
- Reusable issue/methodology library and team collaboration with change tracking, available self-hosted
- Remediation workflow integrations with Jira, Azure DevOps and ServiceNow, plus a token-authenticated REST API
Where Vulnetix adds to it: Dradis is a self-hosted pentest reporting framework; Vulnetix layers on top rather than replacing it. Vulnetix ingests and orchestrates the pentest findings Dradis consolidates (it does not perform the manual testing) into a unified prioritised queue with its own native scanners. Where Dradis stops at import, merge and report templating, Vulnetix adds exploit-intel scoring (EPSS/KEV/ESS/CWSS/LEV), reachability analysis, versioned VEX with audit trail, EOL/SSVC policy and Safe Harbour autofix PRs.
No migration, no rip-and-replace. Dradis keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Dradis results in Vulnetix
Upload Dradis JSON, XML output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.