🛡 Website Security Audit
Passive security scan of any public website. We check HTTP security headers, TLS configuration, cookie flags, mixed content, server fingerprint, known CVEs via the NVD database, CMS detection, mail DNS records and security.txt — without sending any active payloads to your target.
Safe by design
No SQL injection probes, no XSS payloads, no port scans. Only the same HTTP requests a normal browser makes, plus public DNS lookups. Results in ~15 seconds.
Enter a URL to audit …p
Public URLs only. Private/internal addresses are rejected.