⚡ 33 Security Checks · PDF, JSON & HTML Reports · Zero External Tools

Scan. Detect. Secure.

Professional security scanner that crawls your web application and tests for OWASP Top 10 vulnerabilities. Get actionable reports with findings and remediation steps.

Security Checks

33 automated checks grouped into 9 categories - based on OWASP Top 10

Injection Testing

XSS (reflected), SQL injection, command injection, and path traversal/LFI with multiple payload variants.

4 checks

SSL/TLS & Encryption

Certificate validity, protocol version, cipher strength, mixed content, HTTP/2 support, and HTTPS enforcement.

5 checks

Security Headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and X-XSS-Protection.

7 checks

Sensitive Data Exposure

Exposed .env, .git, source maps, private IPs, email addresses, stack traces, and server info disclosure.

6 checks

Misconfiguration

CORS, directory listing, HTTP methods, clickjacking, host header injection, open redirects, and form hijacking.

5 checks

Authentication & Session

Cookie flags (Secure, HttpOnly, SameSite), CSRF tokens, autocomplete on sensitive fields, and SRI integrity.

4 checks

API Security

Endpoint discovery, exposed Swagger/OpenAPI docs, GraphQL introspection, unauthenticated access, and rate limiting.

3 checks

Attack Surface Discovery

Deep crawling (depth 3), subdomain enumeration via CT logs, tech fingerprinting, and WordPress-specific checks.

4 checks

Email & DNS Security

SPF record validation, DMARC policy enforcement, and security.txt responsible disclosure policy.

3 checks