Find vulnerabilities in minutes
The free scan looks at your domain from the outside, without touching the site: TLS certificate and HTTPS redirect, the home page's security headers, DNS hygiene and registration expiry, e-mail authentication, and technical SEO. Try it now for free.
- Home page security headers (CSP, HSTS, Permissions-Policy) and what they give away about your server
- SSL/TLS certificate: validity, expiry and the HTTPS redirect
- DNS and domain: DNSSEC, CAA, dangling subdomain and registration expiry
- Domain e-mail (SPF, DKIM and DMARC)
- Public files and AI search: robots.txt (including the private paths it gives away), sitemap, /llms.txt, structured data and technical SEO
- Real homepage performance: Core Web Vitals (LCP, CLS, INP), the PageSpeed score and what is holding the load back
- A score from 0 to 100 and a report with the evidence behind every finding
Test your app now
How far each level goes
The scan on this page runs right now, with no signup. Creating an account is free and opens the technical analysis inside your app. Paid plans raise how much each analysis covers.
Free scan
on this pageNo signup, no card
Looks at your domain from the outside. It does not browse the site or enter the logged-in area.
- Security headers on the home page (CSP, HSTS, Permissions-Policy)
- TLS certificate: validity, expiry and the redirect to HTTPS
- DNS and domain: DNSSEC, CAA, dangling subdomain and registration expiry
- Domain email: SPF, DKIM and DMARC
- Public files and AI search: robots.txt, sitemap, /llms.txt and technical SEO
- A score from 0 to 100 and one problem from each front on screen
With an account
freeSignup, no card
This is the technical analysis, inside My apps. It goes into the site: it maps the pages, logs in and tests the backend.
- Everything in the free scan, plus its full report with the evidence behind each finding
- 10 analyses per month
- Maps up to 5 pages of the site
- 1 login per analysis, to reach the authenticated area
- Up to 25 API endpoints tested
- Backend and BaaS (Supabase, Firebase and others), payment and privacy
- Pentest with the critical and high severity corpus
- No active DAST pass, no comparison between two logins and no step by step fix
Paid plans
Pro and PremiumThe same analysis, with far more reach
No new test is switched on here. What grows is how much each analysis covers, and the finding starts coming with the fix.
- Everything in the free tier, without the three limits above
- 60 to 200 analyses per month
- 50 to 300 pages mapped per analysis
- 250 to 1500 API endpoints tested
- 2 to 3 logins per analysis, with the cross account reading (what account A reaches in B)
- Active DAST pass against the APIs we find
- Pentest with the corpus up to medium (Pro) and low (Premium) severity
- A step by step fix on every finding, ready to paste into your AI
No plan switches a test off: what changes is how much each one covers, and when a limit cuts, the report says "covered up to your plan limit". Verifying domain ownership unlocks the pentest and takes the BaaS out of read-only mode, and that works the same on every level.