Documentation
Every check, one scanner.
49 scanners running 378+ individual checks — SQLi, XSS, exposed keys, BaaS misconfigs, SSL/TLS grading, plus SEO & AEO visibility, uptime, Core Web Vitals and accessibility. Every finding ships with an AI-ready fix prompt.
SQL Injection Scanner
Detect SQL injection vulnerabilities in your web application before attackers exploit them.
Cross-Site Scripting (XSS) Scanner
Find XSS vulnerabilities that could let attackers inject malicious scripts into your pages.
Security Headers Scanner
Check if your site has the right HTTP security headers to prevent common attacks.
API Key Exposure Scanner
Detect exposed API keys, tokens, and secrets in your frontend code and responses.
SSL/TLS Security Scanner
Verify your SSL/TLS configuration, certificate validity, and encryption strength.
CORS Misconfiguration Scanner
Detect dangerous CORS policies that could allow unauthorized cross-origin access.
CSRF Protection Scanner
Check if your forms and API endpoints are protected against cross-site request forgery.
Cookie & Session Security Scanner
Audit cookie flags, session management, and token security for your application.
Authentication Flow Scanner
Test your login, signup, and password reset flows for common security weaknesses.
DNS & Email Security Scanner
Verify DNS configuration, SPF, DKIM, DMARC records, and domain security.
Open Redirect Scanner
Find URL redirect vulnerabilities that attackers use for phishing campaigns.
GraphQL Security Scanner
Audit your GraphQL API for introspection leaks, injection, and query complexity attacks.
JWT Security Audit
Analyze JSON Web Tokens for weak algorithms, key exposure, and implementation flaws.
Tech Stack & CVE Scanner
Identify your technology stack and check for known vulnerabilities (CVEs).
Threat Intelligence Scanner
Check if your domain or IP appears on blocklists, malware databases, or threat feeds.
Legal Compliance Scanner
Check for privacy policy, cookie consent, terms of service, and GDPR compliance indicators.
DDoS Protection Scanner
Evaluate your site's resilience against distributed denial-of-service attacks.
File Upload Security Scanner
Test file upload endpoints for unrestricted uploads and remote code execution risks.
Audit Logging & Monitoring Scanner
Verify that security events are properly logged and monitored in your application.
Mobile API Rate Limiting Scanner
Check API endpoints for proper rate limiting and abuse prevention on mobile-facing APIs.
Mobile Interface Scanner
Tap-target sizing, horizontal overflow, font legibility, and touch icons at a real mobile viewport.
Domain Hijacking Detection
Detect subdomain takeover vulnerabilities and domain registration security issues.
Debug Endpoints Scanner
Find exposed debug routes, admin panels, and development endpoints left in production.
Input Validation Scanner
Test form fields and API inputs for proper validation and sanitization.
Vercel Hosting Security Scanner
Audit Vercel-specific security settings, headers, and deployment configuration.
Netlify Hosting Security Scanner
Check Netlify-specific security configuration, headers, and deployment settings.
Cloudflare Security Scanner
Audit Cloudflare configuration, WAF settings, and CDN security features.
Dependency Vulnerability Scanner
Scan your project dependencies for known vulnerabilities and outdated packages.
Transitive Dependency Vulnerability Scanner
Resolve every dependency your lockfiles actually install — transitive ones included, across npm, PyPI, Go, Cargo, RubyGems, Composer and Maven — and report the known CVEs against them.
Container & IaC Misconfiguration Scanner
Audit the Dockerfile, Kubernetes manifests, Terraform, CloudFormation and Helm charts in your repository for insecure defaults — root containers, privileged pods, public storage, unpinned base images, secrets passed as build args.
Supabase Security Scanner
Audit your Supabase project for RLS misconfigurations, exposed APIs, and insecure auth settings.
Firebase Security Scanner
Check Firebase Security Rules, authentication settings, and Firestore/RTDB access controls.
GitHub Repository Security Scanner
Audit your GitHub repository's security posture — branch protection, secret scanning, access, webhooks and deploy keys.
GitHub Actions Supply Chain Scanner
Analyze CI workflows for script injection, untrusted-code execution, exposed self-hosted runners, and unpinned third-party actions.
Browser Storage & Session Token Scanner
Detect JWTs, refresh tokens, and session identifiers stored in localStorage or sessionStorage.
Source Code SAST Scanner
Scan every file in a connected GitHub repository for live credentials, committed secret files, and high-risk auth, SQL, CORS, SSRF, TLS and cookie patterns.
Git History Secret Scanner
Walk every commit for credentials that were committed and later deleted — still recoverable, still valid, and invisible to any scan of the current code.
Dependency Supply Chain Scanner
Check lockfile integrity, install-time lifecycle scripts, dependency-confusion exposure, and .gitignore credential gaps.
AI Tooling Configuration Scanner
Scan committed MCP server configs and AI coding-agent settings for inline API keys, unpinned auto-executed servers, and leaked internal endpoints.
Webhook Signature Verification Scanner
Find webhook handlers that appear to trust provider events without verifying signatures.
IDOR & Broken Access Control Scanner
Find exposed admin routes, unauthenticated APIs, sequential IDs, and mass data exposure.
Tenant Isolation Scanner
Use two authenticated test actors to verify tenant-scoped resources cannot be read across accounts.
SEO Scanner
Grade your search visibility with 75 checks — indexability, metadata, structured data, content, links, and Core Web Vitals — plus a live preview of how the page renders when shared.
AEO Scanner (AI Visibility)
Check whether AI answer engines — ChatGPT, Claude, Perplexity, Google AI — can crawl, parse, and cite your site. 46 checks.
Uptime Monitoring & Status Pages
External uptime checks every 60 seconds with incident tracking, down/recovery alerts, and a public status page.
Performance & Core Web Vitals Scanner
Lab diagnostics plus real-user Core Web Vitals from CrUX and RUM — with daily regression alerts before rankings drop.
Accessibility Scanner (WCAG)
WCAG 2.x Level AA signals across structure, forms, navigation, and media — the EAA-relevant checks, automated.
Domain Watchtower
Domain expiry, transfer locks, nameserver drift, DNSSEC, CAA, and certificate runway — watched daily, alerted on change.
Subdomain Enumeration Scanner
Discover subdomains via certificate-transparency logs and a common-name wordlist, and flag any pointing at an unclaimed third-party service.
