xlogs vs Aikido

Aikido is a serious application-security platform, and a good one. It is built for teams with repositories and cloud accounts to connect. xlogs scans a single deployed URL and needs no account at all. These are different jobs, and for a lot of people the honest answer is Aikido.

Try the small version first

Free, read-only, no account. If you need repo and dependency scanning, use a platform like Aikido.

When Aikido is the right answer

If you have a codebase, a team, and CI, Aikido does things xlogs does not attempt: dependency and licence scanning, static analysis of your source, container and cloud posture, and secrets detection across your repository history. Its free Developer tier is genuinely usable, covering 10 repos, 1 domain, 1 cloud account and all core scanning modules with no card.

That tier does have limits worth knowing before you rely on it: 10 AI AutoFixes per month, rescans every 3 days, and the cheapest paid tier is 300 US dollars per month. And every path in requires connecting a repository or a cloud account.

When xlogs fits instead

If you built one app with an AI tool, shipped it, and want to know within a minute whether it is leaking anything, connecting a repository is a larger ask than the question deserves. xlogs takes a URL, needs no account, has no cap on scans or fixes, and answers the specific question of what a stranger can reach right now.

It is a smaller product on purpose. If you outgrow it, a platform like Aikido is the direction to grow into, and we would rather say that than pretend otherwise.

xlogsAikido
What you connectNothing. Paste a URL, or a public repo URL. No account, no OAuth grantA repository or cloud account
Free tierUnlimited scans, findings and fixes10 repos, 1 domain, 10 AI AutoFixes/month, rescan every 3 days
Cheapest paid tierNo paid tier yet300 USD per month
Source code analysisYes, for supply-chain risk: 29 checks on a public repo, read-only, never executed. Not SASTYes, a core strength
Dependency and licence scanningLockfile-pinned npm dependencies checked against the OSV advisory database, plus sources, mirrors and licenceYes
Live database tested anonymouslyYesNot the same check
AI at scan timeNone. DeterministicAI AutoFix, metered on the free tier
Built forOne person with one deployed appEngineering teams
Access log analysisDrop an access log: parsed in your browser, never uploadedNot offered
Joins probes to exposureYes: 40 requests for /.env, and your app serves itNo, it has no access-log side

Common questions

Is xlogs an Aikido alternative?

No, not for a team with a codebase. Aikido scans source, dependencies, containers and cloud, and xlogs does none of that. For checking whether one deployed app is exposing data or keys right now, xlogs is faster and needs nothing connected. Plenty of people need one and not the other.

Why does xlogs have no paid tier?

Because we have not built the thing worth charging for yet. When we do, it will be monitoring and recurrence, not findings or fixes. Those stay free and uncapped.