Website Security Scanner
That Never Stops Watching
Scan free in seconds. Uncover TLS vulnerabilities, missing security headers, exposed API secrets, known-vulnerable JS libraries, and dangling subdomain takeovers — with step-by-step fix code and continuous drift alerts.
Interactive Security Topology & Tree Graph
Unlike traditional scanners that just print flat text checklists, Igris Radar maps your application's complete security topology into an interactive, drill-down graph view.
Live Topology Preview: acme-cloud.io
Click any node to inspect severity, details, and exact remediation advice.
Automated Security Checks
Audit Categories
Agents / Installs Required
Average Full Scan Time
How Do Leading Tech Platforms Score?
We continuously scan the world's most popular platforms for TLS hardening, security headers, and domain trust.
google.com
Apple
apple.com
Cloudflare
cloudflare.com
Stripe
stripe.com
GitHub
github.com
Vercel
vercel.com
How It Works
Three frictionless steps from raw URL to an interactive security report with instant remediation code.
Paste Your Domain
One URL is all it takes. No agents, no plugins, no DNS modifications. Works on any public web application or API.
We Run 90+ Checks
We analyze TLS protocols, headers, DNS authentication, CORS, cookies, sensitive files, JS library CVEs, and discover subdomains.
Get Visual Fixes & Alerts
Explore the interactive topology tree, copy ready-to-paste Nginx/Cloudflare patches, and enable continuous drift monitoring.
90+ Checks. Exact Remediation Snippets.
Browse our automated test methodology across the core security layers.
Content Security Policy (CSP)
Restricts sources from which scripts, styles, and assets can load to prevent XSS and code injection.
HSTS Enabled (Strict-Transport-Security)
Tells browsers to only access your site over HTTPS, preventing protocol downgrade attacks.
HSTS Preload Eligibility
Verifies if your HSTS configuration meets Chromium preload requirements (max-age ≥ 1 year, subdomains, preload).
Frame Security Policy (X-Frame-Options)
Controls whether your page can be embedded in iframes on other sites, protecting against clickjacking.
X-Content-Type-Options Header
Prevents browsers from MIME-sniffing a response away from the declared content-type, stopping script execution from uploads.
Permissions-Policy Header
Controls which browser features (camera, microphone, geolocation, payment) can be used on your page and in iframes.
Referrer-Policy Header
Governs how much referrer information (including URLs and sensitive query parameters) is sent when navigating away.
Set-Cookie Headers (Secure, HttpOnly, SameSite)
Cookie security attributes (Secure, HttpOnly, SameSite) protect session cookies from theft and cross-site attacks.
Cookie Prefix Hardening (__Host- and __Secure-)
Validates that sensitive authentication tokens leverage browser cookie prefixes (__Host- or __Secure-) to prevent cookie tossing.
CORS Misconfiguration & Wildcard Audit
Detects overly permissive Access-Control-Allow-Origin headers or null origins that expose authenticated APIs to cross-origin attackers.
Cross-Origin Resource Isolation (COOP, COEP, CORP)
Evaluates COOP (Cross-Origin-Opener-Policy) and COEP headers to isolate your browsing context from Spectre-like side-channel attacks.
Server Information Disclosure
Checks if Server or X-Powered-By headers reveal software versions (e.g. Apache/2.4.41, PHP/7.4.3), aiding attacker reconnaissance.
X-Powered-By Header Stripping
Ensures frameworks like Express, Next.js, or PHP do not emit X-Powered-By fingerprint headers in responses.
Cache-Control for Sensitive Endpoints
Ensures authenticated and sensitive endpoints return Cache-Control: no-store to prevent caching on shared proxy servers.
Deprecated X-XSS-Protection Header
Checks that legacy X-XSS-Protection is set to 0 or removed to prevent browser XSS auditor vulnerabilities.
Reporting-Endpoints & NEL Header
Inspects Reporting-Endpoints and Network Error Logging (NEL) headers for automated real-time security violation reporting.
Content-Type Header & Charset Declaration
Ensures all HTML/API responses specify an explicit Content-Type with charset=utf-8 to prevent UTF-7 encoding bypasses.
Trusted Types Readiness (DOM XSS Protection)
Evaluates CSP require-trusted-types-for directive to prevent DOM-based XSS by enforcing typed objects.
A Fix Today Can Break on Your Next Deploy
Developers frequently drop headers in staging, rotate DNS records, or accidentally commit .env files. With continuous monitoring, Igris Radar re-scans your domain on a schedule and notifies your team the moment a security regression appears.
Daily automated scan found that Strict-Transport-Security (HSTS) header was removed after recent deploy #149.
Map Scan Results to Regulatory Frameworks
Our findings map directly to controls across major compliance mandates, allowing you to export audit-ready reports for clients and auditors.
Frequently Asked Questions
Common questions about Igris Radar's website security scanner and audit methodology.
How does this scanner differ from SecScanner or Mozilla Observatory?
Most scanners only check basic HTTP headers. Igris Radar runs a comprehensive 90+ check audit: TLS handshake validation, active Certificate Transparency subdomain enumeration, dangling CNAME takeover detection, live CVE lookups for frontend JavaScript libraries, exposed secrets scanning (.env, API keys), and an interactive topology tree graph.
Is the scan completely non-intrusive and safe for production?
Yes, 100%. Our scanner performs passive analysis of headers, certificates, DNS records, and standard HTTP GET requests. We never execute denial-of-service tests, exploit payloads, or invasive penetration attacks.
Do I need to install any code snippets or software?
No installation, agents, or API keys required. You just enter your URL, and the scanner evaluates the site from the perspective of an external visitor or attacker.
What does the AI Remediation Engine provide?
Following each scan, our AI analyst streams an executive summary, threat model attack chains, OWASP Top 10 mappings, and copy-paste code patches tailored specifically to your detected web server (Nginx, Apache, Cloudflare, Next.js).