# AskarLabs > AskarLabs makes security software for developers and site owners. Two product lines: CMS Security (vScan, vPatch) and Identity & Access (PasswordLab). AskarLabs is a security software company. Its current live products are vScan - a continuous vulnerability scanner for WordPress, Joomla, and Drupal - and PasswordLab, a self-hosted password manager for teams. A third product, vPatch (automated patching), is in development. ## Site pages - [Home](https://askarlabs.com/): Overview of AskarLabs, products, and company philosophy. - [Contact](https://askarlabs.com/contact/): Four contact routes - sales, support, security disclosure, and press. Median first reply under 4 working hours. - [Privacy Policy](https://askarlabs.com/privacy/): How AskarLabs collects, uses, and protects personal data. - [Cookie Policy](https://askarlabs.com/cookie/): Cookies in use and how to manage them. - [GDPR Policy](https://askarlabs.com/gdpr/): Data subject rights and GDPR compliance. - [Terms & Conditions](https://askarlabs.com/terms-conditions/): Terms of service for AskarLabs products. ## vScan vScan is a WordPress, Joomla, and Drupal vulnerability scanner. It installs as a lightweight CMS plugin, inventories every component on the site (plugins, themes, core, PHP runtime, web server, PHP extensions), and cross-references each one against a live CVE feed. Results are shown in a filterable dashboard with a 0–100 Security Score. - [vScan landing](https://askarlabs.com/vscan/): Product overview, how it works, capabilities, and FAQ. - [vScan features](https://askarlabs.com/vscan/features/): Full-stack inventory, CVE monitoring, severity scoring, scheduled scans, multi-CMS coverage, and privacy model. - [vScan pricing](https://askarlabs.com/vscan/price/): Plans for individuals, agencies, and hosting providers. Free plan available (1 site, daily scans, no card). Paid plans from $39/year. ## vScan documentation - [Docs index](https://askarlabs.com/docs/): Documentation home for vScan — four sections covering setup, usage, configuration, and reference. - [Overview](https://askarlabs.com/docs/vscan-overview/): What vScan does, key concepts, how a scan works. - [Installation](https://askarlabs.com/docs/vscan-installation/): Requirements, WordPress admin install, FTP install, and uninstall. - [Getting started](https://askarlabs.com/docs/vscan-getting-started/): Get an API key, connect the plugin, run first scan. - [Dashboard](https://askarlabs.com/docs/vscan-dashboard/): Security score, KPI cards, results table, running scans. - [Security score](https://askarlabs.com/docs/vscan-security-score/): How the 0–100 score is calculated — CVSS severity, CVE count, component exposure, fix availability. - [Scanning](https://askarlabs.com/docs/vscan-scanning/): Manual and scheduled scans, scan history, rate limits. - [What gets scanned](https://askarlabs.com/docs/vscan-what-gets-scanned/): Plugins, themes, WordPress core, PHP runtime, web server, PHP extensions. - [Settings](https://askarlabs.com/docs/vscan-settings/): API configuration card, connected state, disconnecting. - [API key](https://askarlabs.com/docs/vscan-api-key/): Key format, domain binding, expiry, renewing. - [Plans](https://askarlabs.com/docs/vscan-plans/): Free vs Premium — scan frequency, CVE feed update speed, email alerts. - [Rate limiting](https://askarlabs.com/docs/vscan-rate-limiting/): Limits by plan (Free: 1/day, Premium: 25/day), reset window, avoiding limits. - [Troubleshooting](https://askarlabs.com/docs/vscan-troubleshooting/): Connection errors, key validation failures, domain binding, stuck scans, display issues. ## PasswordLab PasswordLab is a self-hosted password manager for business teams. Passwords are stored on the customer's own server (AWS, GCP, Azure, DigitalOcean, Linode, or bare metal). AES-256 encryption at rest and in transit, 2FA on by default. Web app, browser extension, and mobile sharing one vault. Per-seat licensing from 5 seats. - [PasswordLab website](https://passwordlab.io): External site for PasswordLab. ## WPAudit WPAudit is a free online security check for any public WordPress site. Runs 13 passive checks — no plugin, no signup, no login needed. Results come back in under a minute with a score and a per-check pass/warn/fail breakdown. - [WPAudit tool](https://askarlabs.com/wpaudit): Free WordPress security audit — enter a URL, get a report. ## Optional - [CVE database](https://askarlabs.com/cve/): Index of CMS CVEs affecting WordPress, Joomla, and Drupal plugins, themes, and core. - [Security.txt](https://askarlabs.com/.well-known/security.txt): Responsible disclosure contact and PGP key location. - [PGP key](https://askarlabs.com/.well-known/askarlabs-pgp.asc): AskarLabs PGP public key (fingerprint: 3D92 056D C27D CD29 46C1 0665 · 269B 29F6 7065 BB55).