Skip to main content
Free tool

Scan a site for what attackers check first

Twenty-five passive checks across six categories — security headers, TLS, cookies, server disclosure, exposed files, and transport hygiene. Results in under thirty seconds. No sign-up.

Passive, non-intrusive checks only. Nothing is stored.

01Headers
02SSL / TLS
03Cookies
04Server exposure
05Exposed files
06Best practices
25+Checks
6Categories
<30sScan Time
3/dayFree Scans

Daily Limit Reached

You've used your 3 free scans today. Try the Lory AI Pentester for autonomous AI penetration testing of your in-scope assets and AI-powered analysis.

Try the Lory AI Pentester Book a Demo
Initializing scan...
0/100
Calculating...
This scan only scratches the surface

Get Autonomous AI Penetration Testing

The Lory AI Pentester runs autonomous AI penetration testing of your in-scope assets, with AI-powered vulnerability analysis, executive reports, and automated alerting.

Try the Lory AI Pentester Book a Consultation
Usage-based pricing Human-reviewed findings No subscription
What We Check

Comprehensive Security Analysis

Our scanner checks for the most common security issues that leave websites vulnerable.

Security Headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, and Referrer-Policy.

SSL/TLS Analysis

Certificate validity, expiration, issuer, protocol support, and HTTPS redirect enforcement.

Cookie Security

HttpOnly, Secure, SameSite flags, and cookie scope analysis on all response cookies.

Server Exposure

Server header leakage, X-Powered-By disclosure, and technology fingerprinting.

Common Files

robots.txt, security.txt, sitemap.xml presence and configuration analysis.

Best Practices

HTTPS enforcement, redirect chains, mixed content indicators, and meta tag analysis.

How It Works

Scan in 3 Simple Steps

Get actionable security insights in seconds.

1

Enter Your URL

Type in any domain or website URL - we'll handle the rest automatically.

2

We Analyze

Our scanner runs 25+ passive security checks across 6 categories in under 30 seconds.

3

Get Your Report

Receive a detailed breakdown with a security score, findings, and actionable recommendations.

Frequently Asked Questions

Is this scanner really free?
Yes, completely free with no sign-up required. We built this tool to help website owners identify common security issues quickly. For a deeper, expert-led assessment, check out our PTaaS platform.
Is it safe to scan my website?
Absolutely. We only perform passive, non-intrusive checks - reading HTTP headers, checking SSL certificates, and looking for common misconfigurations. We never attempt to exploit vulnerabilities or modify anything on your site.
What does my security score mean?
Your score (0-100) reflects how well your site follows security best practices. 80+ is good, 50-79 needs improvement, and below 50 indicates significant issues. The score is based on weighted checks across security headers, SSL/TLS, cookies, and more.
What's the difference between this and a penetration test?
This scanner checks for surface-level misconfigurations and missing best practices. A penetration test goes much deeper - our certified security experts manually test for business logic flaws, authentication bypasses, injection vulnerabilities, and much more.
Do you store my scan results?
No. Scan results are generated in real-time and delivered directly to your browser. We do not store, log, or share any scan data or URLs.

Stop Guessing. Start Testing.

93% of breaches could have been prevented with proactive security testing. The Lory AI Pentester runs autonomous AI penetration testing of your in-scope assets with AI-powered analysis.

Try the Lory AI Pentester Book Consultation
Usage-based — pay for what you run Prepaid credits, 1 credit = $1 No subscription
Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!