Basic Hygiene
Headers, HTTPS, TLS, cookies, server disclosure, and exposure checks.
15 checks
Learn moreScanner packages
Each package is a focused set of non-destructive checks you can run independently against a verified target. Pick one, or run several to build full coverage.
Basic Hygiene
Headers, HTTPS, TLS, cookies, server disclosure, and exposure checks.
15 checks
Learn moreOWASP Starter
CORS, CSP, source maps, open redirects, directory listings, and sensitive files.
14 checks
Learn moreThreat Readiness
WAF/CDN, bot, rate-limit, DDoS readiness, and origin exposure signals.
8 checks
Learn moreAuth & Session
Login, reset, rate-limit, enumeration, and session cookie checks.
15 checks
Learn moreAPI Security
API docs, auth signals, CORS, rate limits, JWT analysis, GraphQL, shadow API, and leakage checks.
16 checks
Learn moreCompliance Evidence
Security contact, privacy policy, and terms evidence checks.
10 checks
Learn moreWeb Quality Evidence
Accessibility, SEO, social, and digital-readiness evidence snapshots.
2 checks
Learn moreAI Security
Safe canary probes for applications with LLM or AI chat interfaces.
10 checks
Learn moreCloud Posture (CSPM)
Read-only AWS/Azure/GCP checks: public storage exposure, open security-group/firewall ingress, and stale IAM credentials.
10 checks
Learn moreMobile Static Analysis (APK/IPA)
Offline static analysis of an uploaded Android APK or iOS IPA: hardcoded secrets, ATS/cleartext-traffic misconfiguration, insecure storage flags, and sensitive permission review. Zero network traffic — the artifact is inspected entirely offline.
1 check
Learn moreConsent-gated active probes — require a signed pentest engagement before they run.
Pentest Basic
Active exploitation probes covering OWASP A01–A07: SQLi, XSS, path traversal, open redirect, auth bypass, IDOR, and BFLA. Requires a signed pentest engagement with client consent.
11 checks
See in pricingPentest Advanced
Active probes for OWASP A03–A10: command injection, SSRF, insecure deserialization, file upload bypass, mass assignment, header injection, and business logic flaws. (XXE is covered by the Pentest Basic package, included with every plan that unlocks Pentest Advanced.) Requires Enterprise plan and a signed pentest engagement with client consent.
9 checks
See in pricingStart with a safe Basic Hygiene scan and turn findings into practical fixes.
Start free scan View pricing