Continuous Monitoring · 90+ Automated Checks · Instant DAST

Website Security Scanner
That Never Stops Watching

Scan free in seconds. Uncover TLS vulnerabilities, missing security headers, exposed API secrets, known-vulnerable JS libraries, and dangling subdomain takeovers — with step-by-step fix code and continuous drift alerts.

90+ checks across 15 security & risk categories Subdomain Radar: enumerates subdomains & checks takeover risks Live CVE detection for JS libraries & AI-ready fix prompts
Exclusive Visual Feature

Interactive Security Topology & Tree Graph

Unlike traditional scanners that just print flat text checklists, Igris Radar maps your application's complete security topology into an interactive, drill-down graph view.

Live Topology Preview: acme-cloud.io

Score: 86/100

Click any node to inspect severity, details, and exact remediation advice.

Passed Warning Critical
Rendering Interactive Security Graph...
0+

Automated Security Checks

0

Audit Categories

0

Agents / Installs Required

<0s

Average Full Scan Time

How It Works

Three frictionless steps from raw URL to an interactive security report with instant remediation code.

1

Paste Your Domain

One URL is all it takes. No agents, no plugins, no DNS modifications. Works on any public web application or API.

2

We Run 90+ Checks

We analyze TLS protocols, headers, DNS authentication, CORS, cookies, sensitive files, JS library CVEs, and discover subdomains.

3

Get Visual Fixes & Alerts

Explore the interactive topology tree, copy ready-to-paste Nginx/Cloudflare patches, and enable continuous drift monitoring.

Full Spectrum Audit

90+ Checks. Exact Remediation Snippets.

Browse our automated test methodology across the core security layers.

Content Security Policy (CSP)

Restricts sources from which scripts, styles, and assets can load to prevent XSS and code injection.

HSTS Enabled (Strict-Transport-Security)

Tells browsers to only access your site over HTTPS, preventing protocol downgrade attacks.

HSTS Preload Eligibility

Verifies if your HSTS configuration meets Chromium preload requirements (max-age ≥ 1 year, subdomains, preload).

Frame Security Policy (X-Frame-Options)

Controls whether your page can be embedded in iframes on other sites, protecting against clickjacking.

X-Content-Type-Options Header

Prevents browsers from MIME-sniffing a response away from the declared content-type, stopping script execution from uploads.

Permissions-Policy Header

Controls which browser features (camera, microphone, geolocation, payment) can be used on your page and in iframes.

Referrer-Policy Header

Governs how much referrer information (including URLs and sensitive query parameters) is sent when navigating away.

Set-Cookie Headers (Secure, HttpOnly, SameSite)

Cookie security attributes (Secure, HttpOnly, SameSite) protect session cookies from theft and cross-site attacks.

Cookie Prefix Hardening (__Host- and __Secure-)

Validates that sensitive authentication tokens leverage browser cookie prefixes (__Host- or __Secure-) to prevent cookie tossing.

CORS Misconfiguration & Wildcard Audit

Detects overly permissive Access-Control-Allow-Origin headers or null origins that expose authenticated APIs to cross-origin attackers.

Cross-Origin Resource Isolation (COOP, COEP, CORP)

Evaluates COOP (Cross-Origin-Opener-Policy) and COEP headers to isolate your browsing context from Spectre-like side-channel attacks.

Server Information Disclosure

Checks if Server or X-Powered-By headers reveal software versions (e.g. Apache/2.4.41, PHP/7.4.3), aiding attacker reconnaissance.

X-Powered-By Header Stripping

Ensures frameworks like Express, Next.js, or PHP do not emit X-Powered-By fingerprint headers in responses.

Cache-Control for Sensitive Endpoints

Ensures authenticated and sensitive endpoints return Cache-Control: no-store to prevent caching on shared proxy servers.

Deprecated X-XSS-Protection Header

Checks that legacy X-XSS-Protection is set to 0 or removed to prevent browser XSS auditor vulnerabilities.

Reporting-Endpoints & NEL Header

Inspects Reporting-Endpoints and Network Error Logging (NEL) headers for automated real-time security violation reporting.

Content-Type Header & Charset Declaration

Ensures all HTML/API responses specify an explicit Content-Type with charset=utf-8 to prevent UTF-7 encoding bypasses.

Trusted Types Readiness (DOM XSS Protection)

Evaluates CSP require-trusted-types-for directive to prevent DOM-based XSS by enforcing typed objects.

Automated Regressions Guard

A Fix Today Can Break on Your Next Deploy

Developers frequently drop headers in staging, rotate DNS records, or accidentally commit .env files. With continuous monitoring, Igris Radar re-scans your domain on a schedule and notifies your team the moment a security regression appears.

Slack, Discord, Email, and Webhook instant alerts
Subdomain takeover early-warning radar
SSL certificate expiration alerts (30, 14, and 3 days out)
#security-alerts (Slack)
Just now
Regression Detected
api.acme-cloud.io

Daily automated scan found that Strict-Transport-Security (HSTS) header was removed after recent deploy #149.

+ Suggested Nginx fix: add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
Audit-Ready Reporting

Map Scan Results to Regulatory Frameworks

Our findings map directly to controls across major compliance mandates, allowing you to export audit-ready reports for clients and auditors.

SOC 2 Type II
ISO 27001
PCI-DSS v4.0
HIPAA Security
GDPR Article 32
NIS2 Directive

Frequently Asked Questions

Common questions about Igris Radar's website security scanner and audit methodology.

How does this scanner differ from SecScanner or Mozilla Observatory?

Most scanners only check basic HTTP headers. Igris Radar runs a comprehensive 90+ check audit: TLS handshake validation, active Certificate Transparency subdomain enumeration, dangling CNAME takeover detection, live CVE lookups for frontend JavaScript libraries, exposed secrets scanning (.env, API keys), and an interactive topology tree graph.

Is the scan completely non-intrusive and safe for production?

Yes, 100%. Our scanner performs passive analysis of headers, certificates, DNS records, and standard HTTP GET requests. We never execute denial-of-service tests, exploit payloads, or invasive penetration attacks.

Do I need to install any code snippets or software?

No installation, agents, or API keys required. You just enter your URL, and the scanner evaluates the site from the perspective of an external visitor or attacker.

What does the AI Remediation Engine provide?

Following each scan, our AI analyst streams an executive summary, threat model attack chains, OWASP Top 10 mappings, and copy-paste code patches tailored specifically to your detected web server (Nginx, Apache, Cloudflare, Next.js).

Audit Your Website Security in 30 Seconds

Free forever for single scans. Discover vulnerabilities before attackers do.