41 scanners running 200+ individual checks — SQLi, XSS, exposed keys, BaaS misconfigs, SSL/TLS grading, plus SEO & AEO visibility, uptime, Core Web Vitals and accessibility. Every finding ships with an AI-ready fix prompt.
Detect SQL injection vulnerabilities in your web application before attackers exploit them.
OpenFind XSS vulnerabilities that could let attackers inject malicious scripts into your pages.
OpenCheck if your site has the right HTTP security headers to prevent common attacks.
OpenDetect exposed API keys, tokens, and secrets in your frontend code and responses.
OpenVerify your SSL/TLS configuration, certificate validity, and encryption strength.
OpenDetect dangerous CORS policies that could allow unauthorized cross-origin access.
OpenCheck if your forms and API endpoints are protected against cross-site request forgery.
OpenAudit cookie flags, session management, and token security for your application.
OpenTest your login, signup, and password reset flows for common security weaknesses.
OpenVerify DNS configuration, SPF, DKIM, DMARC records, and domain security.
OpenFind URL redirect vulnerabilities that attackers use for phishing campaigns.
OpenAudit your GraphQL API for introspection leaks, injection, and query complexity attacks.
OpenAnalyze JSON Web Tokens for weak algorithms, key exposure, and implementation flaws.
OpenIdentify your technology stack and check for known vulnerabilities (CVEs).
OpenCheck if your domain or IP appears on blocklists, malware databases, or threat feeds.
OpenCheck for privacy policy, cookie consent, terms of service, and GDPR compliance indicators.
OpenEvaluate your site's resilience against distributed denial-of-service attacks.
OpenTest file upload endpoints for unrestricted uploads and remote code execution risks.
OpenVerify that security events are properly logged and monitored in your application.
OpenCheck API endpoints for proper rate limiting and abuse prevention on mobile-facing APIs.
OpenDetect subdomain takeover vulnerabilities and domain registration security issues.
OpenFind exposed debug routes, admin panels, and development endpoints left in production.
OpenTest form fields and API inputs for proper validation and sanitization.
OpenAudit Vercel-specific security settings, headers, and deployment configuration.
OpenCheck Netlify-specific security configuration, headers, and deployment settings.
OpenAudit Cloudflare configuration, WAF settings, and CDN security features.
OpenScan your project dependencies for known vulnerabilities and outdated packages.
OpenAudit your Supabase project for RLS misconfigurations, exposed APIs, and insecure auth settings.
OpenCheck Firebase Security Rules, authentication settings, and Firestore/RTDB access controls.
OpenScan your GitHub repository for leaked secrets, misconfigured Actions, and supply chain risks.
OpenDetect JWTs, refresh tokens, and session identifiers stored in localStorage or sessionStorage.
OpenScan connected GitHub repositories for high-risk auth, secret, CORS, SQL, SSRF, and cookie patterns.
OpenFind webhook handlers that appear to trust provider events without verifying signatures.
OpenFind exposed admin routes, unauthenticated APIs, sequential IDs, and mass data exposure.
OpenUse two authenticated test actors to verify tenant-scoped resources cannot be read across accounts.
OpenGrade your search visibility with 68 checks — indexability, metadata, structured data, content, links, and Core Web Vitals.
OpenCheck whether AI answer engines — ChatGPT, Claude, Perplexity, Google AI — can crawl, parse, and cite your site. 46 checks.
OpenExternal uptime checks every 60 seconds with incident tracking, down/recovery alerts, and a public status page.
OpenLab diagnostics plus real-user Core Web Vitals from CrUX and RUM — with daily regression alerts before rankings drop.
OpenWCAG 2.x Level AA signals across structure, forms, navigation, and media — the EAA-relevant checks, automated.
OpenDomain expiry, transfer locks, nameserver drift, DNSSEC, CAA, and certificate runway — watched daily, alerted on change.
OpenPaste your URL and get a complete report with an AI-ready fix prompt for every finding.
Scan your site free