Frequently asked questions

StackFlag monitors public vulnerability databases (NVD, the MITRE CVE List, GHSA, OSV, CISA KEV, EPSS, and Vulnrichment) every hour. When a new vulnerability matches software in your stack, we flag it with a plain-English summary explaining what the problem is, how serious it is, and what you should do about it. Think of it as a security news feed filtered down to only the things that affect you.

No. StackFlag is designed for developers, IT managers, and business owners who are not security specialists. Vulnerability descriptions are rewritten in plain English with clear remediation steps. You describe your software in everyday terms ("we run WordPress on nginx with a PostgreSQL database") and StackFlag handles the technical matching.

After signing up, use the Stack Wizard to describe your software in plain English. StackFlag analyses your description and creates monitors automatically. You can also add monitors manually by searching for specific software names or CVE identifiers. The whole setup takes about two minutes.

We pull from seven sources, updated hourly: the National Vulnerability Database (NVD), the MITRE CVE List (all CNAs), GitHub Security Advisories (GHSA), Open Source Vulnerabilities (OSV), CISA Known Exploited Vulnerabilities (KEV), Exploit Prediction Scoring System (EPSS), and CISA Vulnrichment. This covers the vast majority of publicly disclosed vulnerabilities across all ecosystems.

Yes. StackFlag provides continuous vulnerability monitoring with a triage audit trail (unread, read, acknowledged, dismissed) and timestamped notes. This maps directly to controls in ISO 27001, SOC 2, Cyber Essentials, NIS2, PCI DSS, and NIST 800-53. Your flag history serves as evidence that vulnerabilities were identified, assessed, and actioned.

StackFlag is free during the beta period. All features are available to all users at no cost. We will introduce paid plans in the future, but beta users will be given generous notice and migration terms. Contributors who submit significant bug reports or improvement feedback may receive a free account when paid plans launch. Use the feedback button to share your thoughts.

Yes. You can invite team members from Settings. Team members share the same stacks, flags, and alert configurations. Each person gets their own login and can triage flags independently. CC recipients can also be added to individual monitors to receive alert emails without needing an account.

Absolutely. Use the feedback button (bottom right of any page) to send bug reports, feature requests, or general suggestions. If you tick the credit checkbox, your name or handle can be acknowledged when the feature ships. Contributors who submit significant, actionable feedback may receive a free account when paid plans launch. See product updates for what we've been working on.

Recent updates

All updates
Clearer affected-software lists 2 Sep 2026

Vulnerability pages covering hundreds of products or versions now show the most relevant entries first, with the full list one click away. Those pages load faster and are much easier to scan.

Fewer duplicate alerts 2 Sep 2026

A vulnerability that appears in more than one of our sources could be stored as several separate records, so monitoring it could alert you about the same vulnerability more than once. Sources are now matched together properly, so each vulnerability is recorded once and alerts once.

The vulnerabilities already split this way have now been merged, so the duplicates are gone.

Clearer weakness descriptions 31 Aug 2026

Vulnerability pages show a plain-English name alongside every CWE weakness classification. Previously most of them appeared as a bare code with no explanation.

More accurate fix advice, and fewer repeat alerts 31 Aug 2026

The "What to do" box no longer suggests a version number when a vulnerability affects many vendors and the underlying record does not actually name a fix. In those cases it now points you to the vendor advisories instead of guessing.

Alert emails also stop re-sending for older vulnerabilities when only background scoring data changed, and any alert that is an update to something you have already seen is now labelled as an update rather than as new.

Rebuilt plain-English summaries 20 Aug 2026

Some advisories from feeds that publish little detail had summaries that described the wrong software. Every affected record has been rebuilt from the underlying advisory data, and the summaries now stay blank rather than guess when there is genuinely nothing to describe.

See all product updates