See what an attacker already sees on your site. Graded.
Paste your domain. See what your site already exposes to anyone on the internet, graded, in a couple of minutes. Free to run.
External, read-only scan. We only request public URLs - never log in, never send attack traffic.
30% of sites we scan have a serious problem open right now.
A known-vulnerable library in your bundle. A Grafana dashboard or a Jenkins console answering the public internet. Either one still grades a C, which is why only 70% of the sites we check earn an A or B. A letter tells you that something is wrong. It never tells you which file.
Your site tells strangers more than you think.
Before anyone logs in, your servers hand out headers, certificates, DNS records and files to whoever asks. Most of it is harmless. Some of it is a map. We read all of it - the way an attacker would - and tell you what stands out.
One real leak is a hard fail.
Findings are weighted by how much they actually expose, then rolled into a single A-to-F grade a non-engineer can act on. But an exposed key, a public bucket or an expired certificate pins the report to an F on its own, however clean everything around it looks.
- ·/.env downloadable by anyone
- ·no HTTPS redirect, no HSTS
- ·SPF and DMARC missing
The grade tells you something is wrong. The report tells you which line to change.
Free, you see how bad it is. Unlocked, you see the file, the key, the exact path an attacker requested, and the change that closes it. Here is the same finding, both ways.
You learn that something serious is open, and how bad it is. You do not learn which file, which key, or where to look. Neither does anyone else you send the link to.
- No file name
- No path
- No fix
Your deployment serves /.env to anyone who asks. It holds a live database connection string and a payment-processor secret key. No login, no exploit, one GET request.
Fix: Block dotfiles at the web server so /.env can never be served, then rotate every credential it contained.
Where: Nginx, Apache, or your host's redirects file.
Every finding, named, with the exact path and the change that closes it. This one is real, from the example report.
- The file, named
- The exact path
- The fix, with the config to paste
Your grade is free. $15/month unlocks every finding and its fix, then keeps watching: the moment a bad deploy exposes something new, you get an email - not a monthly report you have to read. Or from $19 once if you just need this one report.
Cancel anytime. If the report isn't worth it, ask for a refund within 14 days.
Three steps. No agent, no access, no attack traffic.
- 1
Paste a domain
Any site you can reach. No account, no install, no permission needed to see what's already public.
- 2
We read the surface
Headers, TLS, exposed files, admin panels, leaked secrets, DNS and email hygiene - all read passively, in parallel.
- 3
Get a graded report
A shareable report at its own private URL: your grade, how many issues we found, and - once unlocked - every fix.
Every scan runs 500+ checks, every time.
Plus 2,000+ daily-synced WordPress plugin rules and a live database of 220,000+ library CVE signatures.
Not sure what a finding means? We explain every one.
Plain-English guides to what an attacker can see on your site, and the one-line fix for each. No jargon for its own sake.
Lovable, Bolt, Cursor, Supabase: see what your app left exposed.
The AI shipped the feature. It never checked what it exposed: a key in the browser, a table anyone can read, the reachable .env. Here is the short list, and how to see it from outside.
- The secrets hiding in your JavaScriptAPI keys, tokens, and credentials that shipped to the browser by accident.
- The files you forgot you deployedThe .env, the backup, the .git folder anyone can download with a URL.
- What an attacker sees before they touch your siteEverything an outsider learns about you without sending a single malicious request.
- The admin panel you left unlockedphpMyAdmin, Grafana, debug toolbars, and error pages open to the world.
- HTTPS, TLS, and the headers that protect your visitorsRedirects, certificates, CSP, cookies, and CORS done right.
- Email spoofing and DNS you never configuredSPF, DMARC, CAA, and the dangling subdomain someone can claim.
- Outdated and unverified code on your pagesOld libraries with public exploits, and third-party scripts with no integrity check.
- Shipping fast without shipping holesA founder's playbook for catching this before your first user does.
Find out what your site is leaking.
Paste your domain. The grade is free, and you'll have it in a couple of minutes.
External, read-only scan. We only request public URLs - never log in, never send attack traffic.
Cancel anytime. If the report isn't worth it, ask for a refund within 14 days.
Or read a real report first →