Free Website Security Scanner

Free Website Security Scanner & Vulnerability Assessment Tool

Run a free online website vulnerability scanner and automated security audit from a single URL. Igris Radar inspects your headers and TLS, hunts for exposed secrets and sensitive files, cross-checks JavaScript libraries against live CVE databases, provides a Subdomain Radar for dangling DNS takeover risks, and generates AI action plans in seconds.

90+ checks across 15 security & risk categories Subdomain Radar: enumerates subdomains & checks takeover risks Live CVE detection for JS libraries & AI-ready fix prompts
0+

automated security & risk checks per scan

0

security categories, from TLS to attack surface

0

severity levels, each with remediation

What this audit actually checks

Every check below runs on every scan. No black boxes: this is the exact coverage you get.

CategoryChecks
Transport, TLS & header security6
Secrets & sensitive exposure5
Vulnerable dependencies & supply chain4
Email, DNS & domain trust3
Domain reputation & threat intelligence4
Attack surface & active probing4
01

Transport, TLS & header security

The response headers and certificate your server presents are your first line of defense. We verify each one and explain exactly what a weakness exposes you to.

HTTPS & HSTS enforcement

Confirms encrypted transport and that browsers refuse downgraded HTTP, blocking man-in-the-middle and protocol-downgrade attacks. Includes HSTS preload eligibility.

Content-Security-Policy deep analysis

Goes beyond presence - flags unsafe-inline, unsafe-eval, wildcard sources, and missing frame-ancestors that quietly defeat your XSS protection.

SSL certificate health

Checks expiry, self-signed and chain validity, and key strength (RSA vs ECC aware), plus the negotiated TLS version and Certificate Transparency logging.

Cookie hardening

Per-cookie Secure / HttpOnly / SameSite checks, plus __Host- / __Secure- prefix verification and session-token entropy analysis.

Cross-origin & clickjacking

X-Frame-Options, COOP / COEP / CORP isolation, and CORS reflection tests that only flag genuinely exploitable policies - not harmless wildcards.

Information disclosure

Server and version banners, verbose error pages, and CMS version leaks that hand attackers a ready-made CVE shortlist.

02

Secrets & sensitive exposure

One leaked key in a client-side bundle can mean a five-figure cloud bill or a full compromise. We scan everything the public can reach.

Exposed API keys & tokens

Scans HTML and JavaScript for AWS, Google, Stripe, Firebase, Slack, GitHub, SendGrid and private-key patterns anyone could harvest.

Exposed files & repositories

Probes for reachable .env files, .git / .svn / .hg / .bzr repos, backup archives, and database dumps left in the web root.

Source map exposure

Detects public .js.map files that hand attackers your original, un-minified source code and business logic.

Debug & admin endpoints

Finds exposed profilers (/actuator, /server-status) and public admin login panels that invite brute-force attacks.

Directory listing & data leaks

Open directory indexes, PII in page source, and secrets accidentally left in HTML comments.

03

Vulnerable dependencies & supply chain

The code you didn't write is still your attack surface. We fingerprint what you load and check it against live vulnerability data.

Known-vulnerable JS libraries (CVEs)

Fingerprints the exact version of every JavaScript library you load and queries the OSV database for published CVEs - pinpointing precisely which version to upgrade to.

Outdated WordPress plugins

Detects plugin versions from the page and compares them against the official wordpress.org release feed.

Subresource Integrity (SRI)

Flags external scripts loaded without integrity hashes - the exact vector behind CDN supply-chain attacks.

Third-party footprint

Inventories every external domain your page loads and the supply-chain risk each one adds.

04

Email, DNS & domain trust

Attackers don't need your server to impersonate your brand - an unprotected domain is enough to send email as you.

SPF & DMARC strength

Not just presence: flags weak SPF (~all / +all) and monitor-only DMARC (p=none) that look configured but don't actually stop spoofing.

DKIM, BIMI & MTA-STS

Verifies mail-signing keys, verified brand indicators, and strict transport policy for inbound email.

DNSSEC & CAA

Confirms DNSSEC signing via a validating resolver, and CAA records that restrict which authorities can issue certificates for your domain.

05

Domain reputation & threat intelligence

Is your domain - or anything it links to - already flagged as malicious? We check the same threat feeds browsers and mail filters use.

Malware / phishing blocklist

Checks your domain against Cloudflare's threat-intelligence resolver. A listing usually means the site is compromised or abused.

Outbound link reputation

Screens the third-party domains your page loads for known-malicious hosts - a classic sign of injected ads or hacked scripts.

Domain age & expiry (RDAP)

Flags newly-registered domains (a strong phishing signal) and domains about to lapse (a hijack and downtime risk).

Domain risk signals

High-abuse TLDs, punycode / homograph, and typosquat-prone naming that hurt trust and email deliverability.

06

Attack surface & active probing

We map what an attacker sees first - every public subdomain, and the endpoints most likely to be exploited.

Subdomain enumeration

Discovers your public subdomains from Certificate Transparency logs - the same passive recon attackers run before an attack.

Subdomain takeover

Tests discovered subdomains for dangling CNAMEs pointing at unclaimed S3, Heroku, GitHub Pages and similar services an attacker could hijack.

Open redirects & GraphQL introspection

Probes for unvalidated redirect parameters and exposed GraphQL schemas that leak your entire API surface.

Exposed services & ports

Checks for open database / admin ports and misconfigured endpoints reachable from the public internet.

The report

Everything your team needs to act

A score without a fix list is trivia. Every report pairs measurement with prioritized, copy-ready remediation, including AI-native fix prompts for your coding assistant.

Severity-ranked findings from critical to low, with every passed check listed for your records

A "why this matters" and "how we test this" explanation on every finding, plus copy-paste remediation and an agent-native AI fix prompt

Streaming AI security analysis: a plain-language executive summary, prioritized top risks, and a remediation plan that writes itself out section by section

On higher tiers the AI adds attack-chain threat modeling, OWASP Top 10 mapping, ready-to-paste config snippets, and GDPR / PCI compliance readiness

A 0-100 security score tracked scan-over-scan, with continuous monitoring and email alerts on higher plans

From URL to fix list in three steps

01

Enter any URL

No installs, no code snippets, no DNS changes. Every audit starts from a single URL, yours or a competitor's.

02

Scanners do the work

Purpose-built engines audit security, SEO, AEO, GEO, brand visibility, and site health, with each check scored and severity-ranked.

03

Fix with AI-ready prompts

Every finding ships with plain-language remediation and an agent-native fix prompt you can paste straight into your AI coding assistant.

Frequently asked questions

Sources & further reading

Scan your site for vulnerabilities now

Free plan includes 10 full scans a month. No credit card required.