Passive security scanner

See what's exposed.In one pass.

Headers, TLS, cookies, and DNS. No crawling, no exploits, no account required.

Coverage

What we inspect

  • Headers & CSP

    Missing or weak security headers, including Content-Security-Policy.

  • TLS & certificates

    Certificate chain, expiry, and transport posture.

  • Cookies

    Secure, HttpOnly, SameSite, and related attributes.

  • CORS & redirects

    Open CORS and HTTPS redirect behavior.

  • DNS mail & CAA

    SPF, DMARC, CAA, and DNSSEC signals.

  • Page integrity

    Mixed content and Subresource Integrity gaps.