Skip to content
FREE · SHAREABLE REPORT

Free domain and website security scanner

Check HTTPS, headers, cookies, exposed files and library vulnerabilities. Get a 0–100 score, clear priorities and a report under its own link — with nothing to install.

FREE SECURITY SCANNER
BR SCANNER / TARGET INPUT READY
PUBLIC DOMAIN

Check the domain. See what an attacker sees.

The scan turns technical configuration, exposure and risk signals into one prioritised report.

Anti-bot verification is loading…

PASSIVE ANALYSIS + LIGHT ACTIVE CHECKS NO EXPLOITS · NO LOGIN · NO TARGET CHANGES
01 / ANALYSIS SCOPE

What the scanner checks

Passive, public signals that form an initial assessment of security hygiene. Each signal is explained in the report with context and a concrete next step.

01 / WEB

Application & transport

Encryption, headers, cookies and application behaviour visible from the public website.

HTTPS / TLSCSP / HSTSCORSCOOKIES
02 / DNS + MAIL

Domain & email

Domain resilience against spoofing, DNS mistakes and email channel compromise.

SPF / DMARCDKIMDNSSEC / CAAMTA-STS
03 / EXPOSURE

Attack surface

Public subdomains, files, panels and lookalike domains that expand exposure.

SUBDOMAINS.GIT / .ENVPANELSTYPOSQUATTING
04 / SUPPLY CHAIN

Code & dependencies

Vulnerable libraries, exposed secrets, source maps and third-party resource risks.

OSV / CVESECRETSSOURCE MAPSSRI
05 / POSTURE

Protection & privacy

Protective layers, trackers, information disclosure and modern stack readiness.

WAF / CDNHTTP/3GDPREOL
06 / DECISION

Actionable report

The score and priorities become concrete fixes and a report ready to share.

0–100 / A–F4 PILLARSPDF / JSONRETEST
03 / FAQ

Frequently asked questions

Do you store scan results?

Yes. We automatically save each report under a hard-to-guess link (/s/…) that anyone who knows it can access. The report expires automatically after 90 days. We do not sell or profile this data.

How many scans can I run?

The free plan allows 2 scans per day from one IP address — enough to check a site and re-verify it after fixes. Need more or scheduled scans? Get in touch.

Is this a penetration test?

No. The scan combines passive response analysis with light active checks, including public paths, OPTIONS methods and CORS configuration. It does not test exploits, authenticate or modify the target. Only a manual penetration test gives the full picture.

Can I scan any website?

The scanner only requests publicly available, non-invasive information. Local and private addresses (localhost, internal networks, metadata IPs) are blocked.

What do the score and grade mean?

The score starts at 100 and drops for missing protections. The letter (A–F) and risk level (low/medium/high) are a shorthand to help prioritise — not a substitute for an audit.

BR / NEXT STEP

Need help understanding the scan result?

If the scanner found a problem or you need more than a public configuration check, we can help you choose the right audit or security test.

NDA · clear scope · direct communication