The scanner

What every scan checks

The same outside-in view an attacker gets — turned into clear, actionable results.

HTTPS & TLS

Verifies the site loads over encrypted HTTPS and that plain-HTTP visitors are redirected to the secure version.

Security headers

Checks the five key response headers that block clickjacking, MIME-sniffing and related browser attacks.

Exposed files & panels

Probes for publicly reachable .git folders, .env files, backup copies, admin panels and debug pages.

Email authentication

Validates SPF, DKIM and DMARC records — the trio that stops attackers from sending email as your domain.

Software versions

Detects WordPress and other stacks, flagging outdated cores, themes and plugins attackers exploit first.

Open ports

Checks whether risky ports — FTP, Telnet, databases — are reachable from the internet.