Free Website Security Scanner & Vulnerability Assessment Tool
Run a free online website vulnerability scanner and automated security audit from a single URL. Igris Radar inspects your headers and TLS, hunts for exposed secrets and sensitive files, cross-checks JavaScript libraries against live CVE databases, provides a Subdomain Radar for dangling DNS takeover risks, and generates AI action plans in seconds.
automated security & risk checks per scan
security categories, from TLS to attack surface
severity levels, each with remediation
What this audit actually checks
Every check below runs on every scan. No black boxes: this is the exact coverage you get.
| Category | Checks |
|---|---|
| Transport, TLS & header security | 6 |
| Secrets & sensitive exposure | 5 |
| Vulnerable dependencies & supply chain | 4 |
| Email, DNS & domain trust | 3 |
| Domain reputation & threat intelligence | 4 |
| Attack surface & active probing | 4 |
Transport, TLS & header security
The response headers and certificate your server presents are your first line of defense. We verify each one and explain exactly what a weakness exposes you to.
HTTPS & HSTS enforcement
Confirms encrypted transport and that browsers refuse downgraded HTTP, blocking man-in-the-middle and protocol-downgrade attacks. Includes HSTS preload eligibility.
Content-Security-Policy deep analysis
Goes beyond presence - flags unsafe-inline, unsafe-eval, wildcard sources, and missing frame-ancestors that quietly defeat your XSS protection.
SSL certificate health
Checks expiry, self-signed and chain validity, and key strength (RSA vs ECC aware), plus the negotiated TLS version and Certificate Transparency logging.
Cookie hardening
Per-cookie Secure / HttpOnly / SameSite checks, plus __Host- / __Secure- prefix verification and session-token entropy analysis.
Cross-origin & clickjacking
X-Frame-Options, COOP / COEP / CORP isolation, and CORS reflection tests that only flag genuinely exploitable policies - not harmless wildcards.
Information disclosure
Server and version banners, verbose error pages, and CMS version leaks that hand attackers a ready-made CVE shortlist.
Secrets & sensitive exposure
One leaked key in a client-side bundle can mean a five-figure cloud bill or a full compromise. We scan everything the public can reach.
Exposed API keys & tokens
Scans HTML and JavaScript for AWS, Google, Stripe, Firebase, Slack, GitHub, SendGrid and private-key patterns anyone could harvest.
Exposed files & repositories
Probes for reachable .env files, .git / .svn / .hg / .bzr repos, backup archives, and database dumps left in the web root.
Source map exposure
Detects public .js.map files that hand attackers your original, un-minified source code and business logic.
Debug & admin endpoints
Finds exposed profilers (/actuator, /server-status) and public admin login panels that invite brute-force attacks.
Directory listing & data leaks
Open directory indexes, PII in page source, and secrets accidentally left in HTML comments.
Vulnerable dependencies & supply chain
The code you didn't write is still your attack surface. We fingerprint what you load and check it against live vulnerability data.
Known-vulnerable JS libraries (CVEs)
Fingerprints the exact version of every JavaScript library you load and queries the OSV database for published CVEs - pinpointing precisely which version to upgrade to.
Outdated WordPress plugins
Detects plugin versions from the page and compares them against the official wordpress.org release feed.
Subresource Integrity (SRI)
Flags external scripts loaded without integrity hashes - the exact vector behind CDN supply-chain attacks.
Third-party footprint
Inventories every external domain your page loads and the supply-chain risk each one adds.
Email, DNS & domain trust
Attackers don't need your server to impersonate your brand - an unprotected domain is enough to send email as you.
SPF & DMARC strength
Not just presence: flags weak SPF (~all / +all) and monitor-only DMARC (p=none) that look configured but don't actually stop spoofing.
DKIM, BIMI & MTA-STS
Verifies mail-signing keys, verified brand indicators, and strict transport policy for inbound email.
DNSSEC & CAA
Confirms DNSSEC signing via a validating resolver, and CAA records that restrict which authorities can issue certificates for your domain.
Domain reputation & threat intelligence
Is your domain - or anything it links to - already flagged as malicious? We check the same threat feeds browsers and mail filters use.
Malware / phishing blocklist
Checks your domain against Cloudflare's threat-intelligence resolver. A listing usually means the site is compromised or abused.
Outbound link reputation
Screens the third-party domains your page loads for known-malicious hosts - a classic sign of injected ads or hacked scripts.
Domain age & expiry (RDAP)
Flags newly-registered domains (a strong phishing signal) and domains about to lapse (a hijack and downtime risk).
Domain risk signals
High-abuse TLDs, punycode / homograph, and typosquat-prone naming that hurt trust and email deliverability.
Attack surface & active probing
We map what an attacker sees first - every public subdomain, and the endpoints most likely to be exploited.
Subdomain enumeration
Discovers your public subdomains from Certificate Transparency logs - the same passive recon attackers run before an attack.
Subdomain takeover
Tests discovered subdomains for dangling CNAMEs pointing at unclaimed S3, Heroku, GitHub Pages and similar services an attacker could hijack.
Open redirects & GraphQL introspection
Probes for unvalidated redirect parameters and exposed GraphQL schemas that leak your entire API surface.
Exposed services & ports
Checks for open database / admin ports and misconfigured endpoints reachable from the public internet.
Everything your team needs to act
A score without a fix list is trivia. Every report pairs measurement with prioritized, copy-ready remediation, including AI-native fix prompts for your coding assistant.
Severity-ranked findings from critical to low, with every passed check listed for your records
A "why this matters" and "how we test this" explanation on every finding, plus copy-paste remediation and an agent-native AI fix prompt
Streaming AI security analysis: a plain-language executive summary, prioritized top risks, and a remediation plan that writes itself out section by section
On higher tiers the AI adds attack-chain threat modeling, OWASP Top 10 mapping, ready-to-paste config snippets, and GDPR / PCI compliance readiness
A 0-100 security score tracked scan-over-scan, with continuous monitoring and email alerts on higher plans
From URL to fix list in three steps
Enter any URL
No installs, no code snippets, no DNS changes. Every audit starts from a single URL, yours or a competitor's.
Scanners do the work
Purpose-built engines audit security, SEO, AEO, GEO, brand visibility, and site health, with each check scored and severity-ranked.
Fix with AI-ready prompts
Every finding ships with plain-language remediation and an agent-native fix prompt you can paste straight into your AI coding assistant.