36 Security Checks · PDF, JSON & HTML Reports · Zero External Tools

Scan. Detect. Secure.

Professional security scanner that crawls your web application and tests for OWASP Top 10 vulnerabilities. Get actionable reports with findings and remediation steps.

Security Checks

36 automated checks grouped into 9 categories - based on OWASP Top 10

Injection Testing

Reflected + DOM-based XSS, POST form injection, SQL injection (GET and POST), command injection, and path traversal/LFI.

7 checks

SSL/TLS & Encryption

Certificate validity, protocol version, cipher strength, mixed content, HTTP/2 support, and HTTPS enforcement.

5 checks

Security Headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and X-XSS-Protection.

7 checks

Sensitive Data Exposure

Exposed .env, .git, source maps, private IPs, email addresses, stack traces, and server info disclosure.

6 checks

Misconfiguration

CORS, directory listing, HTTP methods, clickjacking, host header injection, open redirects, and form hijacking.

5 checks

Authentication & Session

Cookie flags (Secure, HttpOnly, SameSite), CSRF tokens, autocomplete on sensitive fields, SRI integrity. Supports authenticated scanning with cookies, bearer tokens, or custom headers.

4 checks

API Security

Endpoint discovery, exposed Swagger/OpenAPI docs, GraphQL introspection, unauthenticated access, and rate limiting.

3 checks

Attack Surface Discovery

Deep crawling (depth 3), automatic SPA detection with headless browser, subdomain enumeration via CT logs, tech fingerprinting, and WordPress checks.

5 checks

Email & DNS Security

SPF record validation, DMARC policy enforcement, and security.txt responsible disclosure policy.

3 checks