free · no signup · about a minute

See what your site shows an attacker. Right now, for free.

Enter your URL. We fetch your homepage the way a browser does, run deterministic security checks against it, and grade what anyone on the internet can already see.

Read-only — we load one page like a browser. We never probe, attack, or log in.

acmestore.comexample
C
No secrets exposed, but browser protections are mostly missing.
exposed 4 · trapped 1 · ripped off 1
mediumMissing Content-Security-Policy header
mediumInsecure http:// resources on an https page
lowServer technology disclosed via X-Powered-By
Every finding shown free, with the evidence.
no email, no accountread-only, single page fetchresults in about a minuteevery finding shown, free

What we check

Deterministic checks against what your site publicly serves — the same response any visitor, crawler, or attacker gets. No impressions, no AI guesses.

exposed · critical
Exposed secrets

Stripe secret keys, AWS access keys, Firebase configs, and service-role keys sitting in your page source or bundled scripts — visible to anyone who views source.

exposed
Security headers

CSP, HSTS, X-Frame-Options, Referrer-Policy — the protections your site tells browsers to enforce. Missing ones leave the door open to injection and clickjacking.

exposed
Mixed content

Insecure http:// scripts and images loaded on your https pages — anything on the network path can read or rewrite them.

exposed
Email & DNS

SPF and DMARC records. Without them, anyone can send email that looks like it came from your domain.

trapped
Tech fingerprinting

Server and framework version disclosure — headers that tell an attacker exactly which known exploits to try against you.

ripped off
Payment configuration

Test-mode payment keys and misconfigured providers in production — the class of mistake that quietly costs real revenue.

How it works

01 — enter your url

Type your domain and pass a quick bot check. No email, no account — the result is yours immediately.

02 — we fetch one page

We load your homepage exactly like a browser: read the response headers, the HTML, and the scripts it references. Read-only — nothing is probed or attacked.

03 — grade + findings

You get an A–F grade, every finding with its evidence, and the list of checks that passed — on a link you can share or re-run after fixing.

What a URL scan can't see

This scan reads only what your site publicly serves. Your database rules, API routes, auth logic, and everything else that lives in your code stays invisible to it — a clean grade here doesn't mean your code is safe.

For the code itself, there's the full scan.

Read-only access to one repo, the complete checklist, every finding with file and line. One payment, no subscription. Scan your code →

Questions

Is it safe to run on my site?

Yes. We load your homepage once, exactly like a browser visiting it, and read what comes back. We never probe endpoints, try logins, or send attack payloads — it's indistinguishable from a normal page view.

Why is it free?

The URL scan reads what's already public, so it costs us very little to run — and if it finds something, you'll want to know what's in the code behind it. That's the paid scan. No email required either way.

How is this different from the code scan?

This scan sees what your site serves; the code scan reads the code itself — database rules, API routes, auth logic, everything a public fetch can't reach. Different vantage points, different findings.

Can I scan any site?

Only scan sites you own or operate. Results per domain are cached for 24 hours, so repeat scans of the same site return the existing result.

What do you store?

The grade and findings, so your result link keeps working and you can re-check after fixing. No email, no account, no tracking of who scanned what.

One minute from now you'll know what your site is showing everyone.

Free · no signup · protected by Cloudflare Turnstile