1Scan
2Unlock
3Report

Security scan built for SaaS and web apps

Everything in the standard scan, plus CORS, GraphQL introspection, exposed API docs, client-side secrets, source maps, and attack-surface recon — HTTP method enumeration, verbose error disclosure, Host header trust, open redirects, and unauthenticated endpoint exposure, tailored to the endpoint type you're scanning.

We only run passive, read-only checks — no exploitation attempts. Limited to 5 scans/hour and 20/day per visitor.

CORS+ credentials check
GraphQLintrospection probe
6attack-surface recon checks
6endpoint types supported
◈

CORS & credentials

Flags a wildcard or reflected origin combined with credentialed requests — the combination that lets any site act as a logged-in user.

⌁

GraphQL & API docs

Checks common paths for a publicly queryable schema or exposed Swagger/OpenAPI documentation.

◎

Client-side secrets

Pattern-matches same-origin scripts for AWS, Stripe, Google, and Slack keys — never stores the match itself, only where it was found.

▤

Source maps & SRI

Flags exposed .map files and third-party scripts loaded without an integrity attribute.

⌖

Endpoint access surface

Tell us it's a billing, admin, profile, webhook, internal, or public-data endpoint, and we probe the paths that endpoint type commonly exposes — the same first move a threat actor researching your API would make.

↷

Recon: methods, errors, redirects

HTTP method enumeration (TRACE/PUT/DELETE), verbose stack-trace/debug-page disclosure, Host header trust (X-Forwarded-Host reflection), open redirects, and a rate-limit heuristic.