Paste your link. Watch the weak spots appear, with how to close each one.
Nine checks run at once, read-only, on a site you have proven is yours. You get back only what we could prove, in plain words, with the exact change to make.
Free. No card. No plugin. Nothing on your site changes.
9 checks
Run at once, in one pass.
0 guesses
Not proven, not reported.
0 changes
Read-only. Your site is never modified.
Free
No card, no time limit.
How it works
- 01
Prove it is yours
One DNS record or one file, once per site. It is also why nobody can point this scanner at your site but you.
- 02
Nine checks run at once
Security headers, TLS, cookies, SPF and DMARC, open redirects, and safe probes for XSS, SQL injection, access control and leaked keys. Read-only, on your domain only.
- 03
You make the change, then scan again
Each finding comes in plain words, with how we proved it and the exact change to make. Apply it, scan again, and watch it come back clean.
Nine questions your site should be able to answer.
We ask them for you, and bring back each answer with what to change.
Can someone send email as you?
Without SPF and DMARC, nothing tells inboxes to reject mail forged in your name. We read both records and tell you exactly what to publish.
Check any domain now, no sign-inSPF · DMARC
Is your padlock about to break?
An expired or mismatched certificate puts a full-page warning in front of every visitor. We check that HTTPS works and flag a certificate that expires within two weeks.
TLS · HTTPS
Are your browser defenses switched on?
Four response headers stop whole classes of attack before they start. We check each one and give you the exact line to add.
CSP · HSTS · X-Frame-Options · nosniff
Are your keys sitting in public code?
API keys shipped in your JavaScript can be read by anyone. We scan your scripts and show which key leaked, masked, so the report never spreads it.
JavaScript
Can one visitor open another person’s data?
We request neighboring records the way a visitor would, and report it only when a different owner’s data comes back.
IDOR · BOLA
Do your cookies guard the session?
A cookie without Secure, HttpOnly and SameSite can be read by a script or sent where it should not go. We check every cookie your home page sets, and never store its value.
Secure · HttpOnly · SameSite
Does your site echo code back?
If a parameter comes back unescaped, a single link can run script in your visitors’ browsers. We test with a harmless marker.
XSS
Does one quote mark break your database?
We add a single quote to your parameters and look for a database error in the reply. Nothing is changed, nothing is extracted.
SQLi
Can a link on your domain send people anywhere?
An open redirect lends your trusted address to phishing links. We try the usual redirect parameters with a harmless address.
?next= · ?url= · ?redirect=
Nobody can point this at a site they do not own. Including yours.
Questions
It costs nothing to look.
Paste your link, prove it is yours, and in a few minutes you will know what is open and how to close it. If your site is clean, we will say so, plainly.