Defensive Agentic Security

We analyze website security in real-time.

Oni X sits in your Chrome extensions. The moment you open any site, our defensive AI agent inspects its security health, uncovers potential breach vectors, and delivers step-by-step hardening instructions.

Sign Up for waitlist
Oni X ONI X EXTENSION v3.0
ACTIVE ON TAB
Target Domain
https://finance-portal.app
Security Score
64 / 100
[!] Vulnerability Detected: Missing CSP
Scanning client DOM scripts & headers...
✓ Generated automated CORS & Header patch.
Real-Time Audit Chrome Extension Active
Scroll to inspect
01 — Capabilities

Defensive intelligence before the exploit occurs.

Oni X evaluates target web architectures in real-time as you browse, executing non-invasive breach modeling to score security health and outline concrete mitigation strategies.

01 / Extension Audit

Instant Chrome Toolbar Analysis

Sits silently in your Chrome extensions. Inspects HTML structures, headers, API endpoints, SSL/TLS, and client JS scripts the moment a tab opens.

02 / Exploit Vectors

Breach & Attack Path Mapping

Exposes exactly how an attacker could hack the site—from XSS, CSRF, and SQLi to misconfigured CORS policies and exposed API keys.

03 / Remediation

Step-by-Step Fortification Guide

Generates actionable patch protocols, server header rules, and copy-paste code fixes to make the target website bulletproof.

04 / Risk Scoring

Agentic Vulnerability Health Score

Calculates a dynamic risk score powered by an LLM defensive agent trained on real-world exploit graphs and OWASP threat intelligence.

02 — Workflow

Three steps from weakness to fortification.

How Oni X turns complex security research into instantaneous, actionable browser intelligence without disrupting your browsing flow.

Phase 01 3D HEX MATRIX TILE SCANNER

1. Extension Reads Target Site

As you navigate the web, Oni X's background extension agent inspects client-side JS bundles, HTTP security headers, cookie flags, and endpoint configurations in real time.

0x4F
0x89
0x12
0xBC
0x77
0xAA
0xDE
0x91
0x34
0xFF
0x08
0x88
0x55
0x23
0x99
0x10
0x64
0x00
Phase 02 HEATMAP THERMAL MATRIX

2. AI Agent Maps Breach Risks

Our defensive AI models simulate attack pathways, identifying OWASP Top 10 vulnerabilities, weak encryption, API leaks, and exploit preconditions.

CRITICAL
EXPLOIT
CORS
CSP
JWT
XSS
AUTH
SQLi
API
RCE
LEAK
TOKEN
PROXY
BOUND
SSL
HASH
REPLAY
HEADER
MITM
ORIGIN
SPOOF
SANIZ
PORT
BREACH
Phase 03 3D BLUEPRINT CODE PATCH TILES

3. Step-by-Step Security Blueprint

Oni X produces a clear security report detailing how weak the site is, how it could be compromised, and exact steps developers can take to strengthen it.

[PATCH 01] CSP Header
default-src 'self'
[PATCH 02] CORS Origin
Access-Control: app.io
[PATCH 03] Clickjacking
X-Frame-Options: DENY
[PATCH 04] HSTS Transport
max-age=31536000
[PATCH 05] Cookie SameSite
Set-Cookie: Strict
[PATCH 06] X-Content-Type
nosniff
[PATCH 07] Referrer Policy
no-referrer
[PATCH 08] Permissions
camera=(), geo=()
Proactive Defense

The ultimate security is knowing where you are weak before someone else does.

Pricing

Choose Oni X
Beta v1. Releasing Soon

Monthly Yearly beta pricing!

Oni X Lite

Coming Soon
$9.99 /month USD

A defense-based tool acting like a real-time spell-checker for your website.

Join Waitlist
Lite Features
  • Everything in Beta
  • Advanced real-time DOM auditing
  • Automated code patch blueprints
  • Fully offline & secure by default

Oni X Beta

Current Version
$0 /forever

The early-access Chrome extension. Like Lite, but in active beta testing.

Download Beta
Included Features
  • Passive posture analysis
  • Zero active attacks
  • Experimental Agentic AI support

Oni X Elite

Requires KYC
$49.99 /month USD

Active attack-based penetration tool. Burp Suite alternative.

Apply for Access
Elite Features
  • Active payload injection
  • Deep SQLi & XSS fuzzing capabilities
  • Strict ID, Age, and Bot Verification
  • Professional Desktop Application
FAQ

Question?, we got you.

How does Oni X know what website I'm analyzing?

×
Oni X sits in your Chrome extension bar. As you navigate the web, it reads client-side DOM trees, HTTP security headers, cookie flags, and endpoint configurations in real-time without requiring manual URL inputs or interrupting your browsing flow.

Is my screen data or browsing history sent to the cloud?

×
No. Security scans are executed client-side directly inside your browser session. Only structured security context (not raw browsing history or passwords) is evaluated to generate defensive responses. Your privacy is foundational.

What browser version or OS is required?

×
Oni X requires Chrome version 110 or later (or any Chromium-based browser such as Brave, Edge, or Arc). Built natively with ultra-lightweight Manifest V3 background workers for exceptional performance.

Does Oni X provide code remediation blueprints for identified risks?

×
Yes. When security vulnerabilities are detected (such as missing CSP headers, exposed API keys, or CORS misconfigurations), Oni X generates copy-paste remediation blueprints so developers can patch their web applications.

How does Oni X Elite verify I own the target website?

×
To prevent unauthorized attacks, Oni X Elite requires strict Target Authorization. You must generate a dynamic SHA-256 token from the Elite Dashboard and host it on your website's .well-known path. The Elite backend verifies this token before any active payloads can be injected.

Why does Oni X Elite require ID verification (KYC)?

×
Because Oni X Elite is an active penetration testing tool capable of executing deep SQL injection and XSS fuzzing, we mandate strict Know Your Customer (KYC) compliance. This ensures the tool is used strictly by ethical hackers and authorized security professionals.

Can I specify exactly which attacks Oni X Elite is allowed to run?

×
Absolutely. When configuring your target in the Dashboard, you explicitly define the Allowed Scopes (e.g., only "SQL Injection" or "CORS Misconfiguration"). The extension's Elite Service strictly enforces these boundaries and will instantly block unauthorized modules.

Is Oni X Elite a cloud scanner or does it run locally?

×
Like Beta and Lite, Oni X Elite runs locally as a Chrome Extension directly from your browser session. However, the target authorization checks and scope management are handled securely through the Oni X Python backend to prevent client-side bypasses.
03 — Metrics

High performance browser security audit.

01-Sec Real-time extension scan speed
100% OWASP Top 10 & vulnerability mapping
3-Step Diagnosis: Weakness → Hack Vector → Fortification
Offensive Security // Oni X

Protect your web applications with Oni X.

Install the Chrome extension to audit any website instantly. Know your vulnerabilities, understand your breach risks, and fortify your code in minutes.

Add to Chrome
Early Access Enrollment

Sign Up for the Oni X Waitlist

Get priority early access to the autonomous Chrome extension security breach scanner before our public release.

148 developers & researchers currently on waitlist.
Oni X Agent Live Breach Analyzer

Enter any web URL below to run Oni X's real-time AI security audit agent.

[ONI-X AGENT v3.0] Ready. Enter a domain and click "Run AI Audit".
Admin Login — Waitlist Dashboard

Enter authorized credentials to view waitlist signups and send invitations.

Oni X Waitlist Admin Dashboard
Logged in: OniX
TOTAL SIGNUPS
0
PENDING INVITES
0
APPROVED / INVITED
0

Waitlist Email Entries

# Email Address Signup Date Status Quick Actions
Oni X Agent Live Breach Analyzer

Enter any web URL below to run Oni X's real-time AI security audit agent.

[ONI-X AGENT v3.0] Ready. Enter a domain and click "Run AI Audit".
Admin Login — Waitlist Dashboard

Enter authorized credentials to view waitlist signups and send invitations.

Oni X Waitlist Admin Dashboard
Logged in: OniX
TOTAL SIGNUPS
0
PENDING INVITES
0
APPROVED / INVITED
0

Waitlist Email Entries

# Email Address Signup Date Status Quick Actions