Passive security scanner
See what's exposed.In one pass.
Headers, TLS, cookies, and DNS. No crawling, no exploits, no account required.
Coverage
What we inspect
Public, non-intrusive checks only.
Headers & CSP
Missing or weak security headers, including Content-Security-Policy.
TLS & certificates
Certificate chain, expiry, and transport posture.
Cookies
Secure, HttpOnly, SameSite, and related attributes.
CORS & redirects
Open CORS and HTTPS redirect behavior.
DNS mail & CAA
SPF, DMARC, CAA, and DNSSEC signals.
Page integrity
Mixed content and Subresource Integrity gaps.