Total Scans
Most Used Server
Most Used Platform
Today Scan's
Do you need the full picture?
Our free, light scans return limited results.
To experience the full power of our security testing toolkit, subscribe now to use 40+ scan tools and features with no scan limits.
Testing areas & features | Free / Light | Premium |
---|---|---|
Fingerprint web server software | Yes | Yes |
Analyze HTTP headers for security misconfiguration | Yes | Yes |
Check the security of HTTP cookies | Yes | Yes |
Check the SSL certificate of the server(Valid or Expired) | Yes | Yes |
Check if the server software is affected by known vulnerabilities | Yes | Yes |
Analyze robots.txt for interesting URLs | Yes | Yes |
Check client access files policy | Yes | Yes |
Discover server configuration problems (ex. directory listing at home page) | Yes | Yes |
Check if HTTP TRACK/TRACE methods are enabled | Yes | Yes |
Check if security.txt is missing on the server | Yes | Yes |
Check if HTTP OPTIONS methods are enabled | Yes | Yes |
Check if HTTP PUT methods are enabled | Yes | Yes |
Check if CORS is misconfigured | Yes | Yes |
CMS Detection | Yes | Yes |
Communication is not Secure (HTTP or HTTPS) | Yes | Yes |
Crawl website | - | Yes |
Check for SQL Injection | - | Yes |
Check for Cross-Site Scripting | - | Yes |
Check for Local File Inclusion and Remote File Inclusion | - | Yes |
Check for OS Command Injection | - | Yes |
Check for ASP Cookieless Cross-Site Scripting | - | Yes |
Check for Server Side Request Forgery | - | Yes |
Check for Open Redirect | - | Yes |
Check for Broken Authentication | - | Yes |
Check for PHP Code Injection | - | Yes |
Check for JavaScript Code Injection | - | Yes |
Check for Ruby Code Injection | - | Yes |
Check for Python Code Injection | - | Yes |
Check for Perl Code Injection | - | Yes |
Check for Log4j Remote Code Execution | - | Yes |
Check for Server-Side Template Injection | - | Yes |
Check for ViewState Remote Code Execution | - | Yes |
Check for Client-Side Prototype Pollution | - | Yes |
Check for Exposed Backup Files | - | Yes |
Check for Request URL Override | - | Yes |
Check for Client-Side Template Injection | - | Yes |
Check for HTTP/1.1 Request Smuggling | - | Yes |
Check for XML External Entity attacks | - | Yes |
Check for outdated JavaScript libraries | - | Yes |
Find administrative pages | - | Yes |
Check for sensitive files (archives, backups, certificates, etc) | - | Yes |
Attempt to find interesting files / functionality | - | Yes |
Check for information disclosure issues | - | Yes |
Clear text submission of credentials | - | Yes |
Verify domain sources | - | Yes |
Check for commented code/debug messages | - | Yes |
Find login interfaces | - | Yes |
Sensitive data detection | - | Yes |