Everything in the standard scan, plus CORS, GraphQL introspection, exposed API docs, client-side secrets, source maps, and attack-surface recon — HTTP method enumeration, verbose error disclosure, Host header trust, open redirects, and unauthenticated endpoint exposure, tailored to the endpoint type you're scanning.
We only run passive, read-only checks — no exploitation attempts. Limited to 5 scans/hour and 20/day per visitor.
Flags a wildcard or reflected origin combined with credentialed requests — the combination that lets any site act as a logged-in user.
Checks common paths for a publicly queryable schema or exposed Swagger/OpenAPI documentation.
Pattern-matches same-origin scripts for AWS, Stripe, Google, and Slack keys — never stores the match itself, only where it was found.
Flags exposed .map files and third-party scripts loaded without an integrity attribute.
Tell us it's a billing, admin, profile, webhook, internal, or public-data endpoint, and we probe the paths that endpoint type commonly exposes — the same first move a threat actor researching your API would make.
HTTP method enumeration (TRACE/PUT/DELETE), verbose stack-trace/debug-page disclosure, Host header trust (X-Forwarded-Host reflection), open redirects, and a rate-limit heuristic.