What this tool checks
- SSL/TLS validity and HTTP → HTTPS redirect
- Secure, HttpOnly and SameSite cookie flags
- Resources loaded over HTTP on an HTTPS page (mixed content)
- Security headers and version disclosure
- security.txt and HTTP/2
- Software and services in use
How to use it
- 01
Enter the site address; you can scan a specific page too.
- 02
Press Scan.
- 03
Share cookie and mixed content findings with your developers — most are one-line configuration changes.
Technical details
Passive scan
The tool reads only the page you enter and the security.txt file. It doesn't submit forms, try logins or look for hidden directories or files, so it's safe to use on live systems.
Cookie flags
Secure keeps a cookie on HTTPS only; HttpOnly stops JavaScript from reading it; SameSite keeps it out of cross-site requests.
Mixed content
Scripts or styles loaded over HTTP on an HTTPS page let an attacker on the network alter your page. Browsers block most of them, which can also break the page.
Frequently asked questions
Does this replace a penetration test?
No. It's an automated, passive first check. Authentication, authorization and business logic flaws only surface in a web application penetration test performed by experts.
Can I scan pages behind a login?
No, the tool only sees the public response. We plan comprehensive tests for authenticated areas.
Which cookie settings should I use?
For session cookies: Secure; HttpOnly; SameSite=Lax (or Strict). Cookies needed in third-party contexts must use SameSite=None; Secure.
Will scans slow down my site?
No. A scan is a handful of requests to the homepage — no different from a normal visitor.