Application & transport
Encryption, headers, cookies and application behaviour visible from the public website.
Check HTTPS, headers, cookies, exposed files and library vulnerabilities. Get a 0–100 score, clear priorities and a report under its own link — with nothing to install.
The scan turns technical configuration, exposure and risk signals into one prioritised report.
Anti-bot verification is loading…
Passive, public signals that form an initial assessment of security hygiene. Each signal is explained in the report with context and a concrete next step.
Encryption, headers, cookies and application behaviour visible from the public website.
Domain resilience against spoofing, DNS mistakes and email channel compromise.
Public subdomains, files, panels and lookalike domains that expand exposure.
Vulnerable libraries, exposed secrets, source maps and third-party resource risks.
Protective layers, trackers, information disclosure and modern stack readiness.
The score and priorities become concrete fixes and a report ready to share.
Guides that help you understand the result, set priorities and get the most out of the scan.
Every scanner test explained step by step — from HTTPS to Certificate Transparency.
What the grade, risk level and individual gaps mean — and how to fix them.
What information about your company is publicly available and how it gets used.
Yes. We automatically save each report under a hard-to-guess link (/s/…) that anyone who knows it can access. The report expires automatically after 90 days. We do not sell or profile this data.
The free plan allows 2 scans per day from one IP address — enough to check a site and re-verify it after fixes. Need more or scheduled scans? Get in touch.
No. The scan combines passive response analysis with light active checks, including public paths, OPTIONS methods and CORS configuration. It does not test exploits, authenticate or modify the target. Only a manual penetration test gives the full picture.
The scanner only requests publicly available, non-invasive information. Local and private addresses (localhost, internal networks, metadata IPs) are blocked.
The score starts at 100 and drops for missing protections. The letter (A–F) and risk level (low/medium/high) are a shorthand to help prioritise — not a substitute for an audit.
If the scanner found a problem or you need more than a public configuration check, we can help you choose the right audit or security test.