[ Free security check ]

Free security check for your web application

Enter your website and work email. We check what any visitor's browser can see: framework and library versions, known vulnerabilities, leaked keys, source maps and security headers.

  • Angular, AngularJS, React, Next.js and Vue
  • Report in a few minutes
  • Fix steps for every finding

Start the check

What we check

Six groups of checks

The problems we find most often when we take over and modernise web applications.

[ versions ]

Framework and library versions

We read the versions your site ships and compare them with support schedules and public vulnerability databases.

[ secrets ]

Keys in JavaScript bundles

API keys, access tokens and private keys that ended up in the code your server sends to every visitor.

[ source ]

Public source maps

A reachable .map file lets anyone download your original source code, with comments and internal API addresses.

[ xss ]

Code that turns off XSS protection

Calls that skip the framework's sanitising, such as bypassSecurityTrust* in Angular or dangerouslySetInnerHTML in React.

[ headers ]

Security headers and TLS

Content Security Policy, HSTS, cookie flags, certificate validity and TLS versions.

[ legacy ]

Out-of-support technology

AngularJS, Vue 2, old jQuery and Bootstrap versions that no longer get fixes, and what to move them to.

How it works

Four steps, a few minutes

  1. [ 01 ]

    Enter your website and work email

    The email has to be on the same domain as the website, e.g. anna@acme.com for acme.com.

  2. [ 02 ]

    Click the link we send you

    It confirms you work at the company that owns the site. We don't scan sites for people from outside the company.

  3. [ 03 ]

    We run the check

    The scanner makes the same requests a browser makes when someone opens your site. No login attempts, no attack payloads.

  4. [ 04 ]

    You get the report

    By email and as a private link valid for 30 days. Each finding says what we found, why it matters and how to fix it.

See a sample report

A report for a fictional shop running Angular 15, with 10 findings and fix steps for each.

Open the sample report

FAQ

Frequently asked questions

Is it really free?

Yes. You get the full report without a call or a contract. If you want help with the fixes, our engineers can take them on.

Can the scan slow down or break my site?

No. The scanner downloads the page and its scripts once, the same way a visitor's browser does. It doesn't submit forms, log in or send attack payloads.

Why do you need a work email?

A security report shows where a website is weak. We send it only to someone who can prove, by clicking a link in their inbox, that they work at the company that owns the domain.

Who can see my report?

Only people with the private link, which we send to the email you confirmed. We don't publish results or rankings. The report is deleted after 30 days.

What does the check not cover?

It sees what is publicly available: the page, its JavaScript and HTTP responses. It doesn't see your source repository, pages behind a login or your backend. Those we review together with your team.

Which technologies does it support?

Headers, TLS, keys, source maps and libraries are checked on any site. Version and support checks cover Angular, AngularJS, React, Next.js, Vue and the common jQuery-era libraries.

Need more than an outside scan?

This scan only sees what your site shows the public. Our engineers review the code, admin panel and integrations, and fix what they find.