Paste a URL. Get a full security autopsy in 30 seconds. Plain-English explanations, zero jargon.
Free · No account required · Results valid for 7 days

The prompt that started it all.
Enter any website URL — no login, no setup, no install.
Headers, SSL, secrets, DNS, cookies, and more — all in parallel, all passive.
Severity-rated findings with plain-English explanations and AI fix prompts.
45+ passive security checks — all legal, no active probing
CSP, HSTS, X-Frame-Options, CORS, referrer policy, and more.
Certificate validity, TLS version, HTTP→HTTPS redirects, HSTS preload.
API keys, tokens, and credentials leaked in HTML or JS bundles.
Overly permissive cross-origin policies that expose your API.
HttpOnly, Secure, and SameSite flags on all session cookies.
.env, .git/config, phpinfo, and other exposed sensitive files.
SPF, DMARC, DKIM, MTA-STS to prevent email spoofing.
Subdomain discovery, takeover risks, CAA records, DNSSEC.
Start free. Upgrade when you need more.
No account. No credit card. Results in 30 seconds.