Every scan runs real security checks drawn from years of penetration testing. Not checkbox compliance - the same methodology a researcher would use against your app.
How to fix these findingsLast 24 hours
We don't just detect these vulnerabilities. We prove they're exploitable on your app with safe, non-destructive proof-of-concept payloads.
Detects Apache Tomcat servers whose HTTP/2 connector mixes headers between requests on the same connection. The compression scheme HTTP/2 uses for headers keeps a shared table that both sides have to agree on for the whole connection. On these versions Tomcat checks each header for illegal characters from inside that shared decoder, and when it finds one it stops reading the rest of the request's headers but keeps the connection open. Everything after the rejected header is therefore never recorded, so the two sides no longer agree on the table, and every later request on that connection resolves indexed headers to the wrong values. We show that with two connections. On the first, a marker header is stored and then re-used by index on a second request, which answers. On the second connection that same second request goes unanswered, because one extra header with a trailing space was placed ahead of the marker. Upgrade Tomcat to 11.0.26, 10.1.60 or 9.0.122. Until you upgrade, turn HTTP/2 off on every connector.
Added 7d ago
Detects services that clone attacker-influenced repositories with a git build older than the July 2025 fix, where a plain recursive clone runs attacker code. Git strips a trailing carriage return when it reads a config value but does not quote one when it writes it, so a submodule whose recorded path ends in a carriage return gets written into the submodule config and read back as a shorter, different path. A symlink committed at that shorter path redirects the submodule checkout, and because the redirect comes from config rather than the working tree, git writes through it without the usual symlink protections. Point it at the submodule hooks directory, track an executable post-checkout file in the submodule, and git runs that file to finish the very checkout that created it. We prove it by reading our own marker, a product only the target could compute, and the uid of the clone process out of the clone log. Repository importers, CI and build runners, mirrors and docs pipelines are the exposed surface. In the CISA known-exploited catalogue since August 2025. Upgrade git to 2.50.1, 2.49.1, 2.48.2, 2.47.3, 2.46.4, 2.45.4, 2.44.4 or 2.43.7.
Added 8d ago
Detects vm2 sandboxes that an attacker can break out of through WebAssembly.compileStreaming or WebAssembly.instantiateStreaming, yielding code execution on the host. On Node.js 26 those two calls hand the sandbox a Promise whose prototype belongs to the host, so vm2's own then/catch overrides and its species hardening never run on it. Guest code plants its own Symbol.species on that Promise and calls finally(), which delivers the raw host-realm error straight into the sandbox; the error's Function constructor then compiles code in the host realm and yields the host process object. We prove it by running a shell command on the host and reading back a product only the target could have computed. No unsafe configuration is needed: a default new VM() with no host objects exposed is enough, so anyone who can submit JavaScript owns the machine. This is a bypass of the earlier WebAssembly JSPI fix. vm2 3.10.1 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.
Added 10d ago
Unauthenticated API access, exposed admin and debug endpoints, CSRF protection, and host header injection, tested with real credentials
Tests whether JSON API endpoints discovered during authenticated crawling also return data without credentials
Example: API endpoint returns data without authentication
Validates CSRF defenses on state-changing forms and endpoints
Example: CSRF token missing on password change form
Probes common admin, debug, API documentation, and monitoring endpoints and records which are accessible
Example: Server metrics readable by anyone
Tests for host header manipulation that can poison password reset links and caches
Example: Host header injection in password reset emails
Exposed files, secrets, technology fingerprinting, and active vulnerability probing
Probes for accidentally exposed files like .env, .git directories, and database backups
Example: .env file publicly accessible with database credentials
Fingerprints frameworks, libraries, and server versions to identify known vulnerabilities
Example: Running Laravel 10.48 with 3 known CVEs
Checks WordPress plugins and themes against known vulnerability databases
Example: Contact Form 7 plugin has known XSS vulnerability
Finds API keys, tokens, and credentials exposed in JavaScript and HTML source code
Example: API key found in client-side JavaScript bundle
Detects stack traces, debug pages, and verbose error messages that reveal internals
Example: Full stack trace exposed in 500 error response
Actively proves whether known CVEs are exploitable on your app, not just present
Example: CVE-2024-1234 confirmed exploitable on this server
Tests for technology-specific misconfigurations like debug modes and exposed admin panels
Example: Laravel debug mode enabled, exposing environment variables
Analyzes JSON Web Token signing configuration and algorithm weaknesses
Example: JWT accepts 'none' algorithm, bypassing signature verification
Tests whether URL parameters can redirect users to malicious external domains
Example: Redirect parameter accepts arbitrary external URLs
Finds framable pages with forms that change state, where an invisible overlay can make a visitor submit them
Example: Password change form can be framed from another origin
Detects vulnerable JavaScript libraries loaded from CDN URLs with known CVEs
Example: jQuery 3.4.1 loaded from cdnjs has 6 known CVEs
HTTP response headers, caching policies, content security, and cookie settings
Checks for missing or misconfigured HTTP security headers like X-Frame-Options and HSTS
Example: Missing Content-Security-Policy header
Deep analysis of CSP directives for bypasses and unsafe-inline usage
Example: CSP allows unsafe-inline scripts
Identifies caching misconfigurations that could leak sensitive data to shared caches
Example: Cache-Control missing on authenticated page
Validates Content-Type headers and MIME sniffing protection
Example: Missing X-Content-Type-Options header
Checks cookie security flags including Secure, HttpOnly, and SameSite attributes
Example: Session cookie missing HttpOnly flag
Fingerprints CDN and WAF providers from response headers and behavior
Example: Cloudflare WAF detected with default ruleset
Probes for dangerous HTTP methods like PUT, DELETE, and TRACE that should be disabled
Example: TRACE method enabled, echoing request headers back to the caller (XST)
Checks .well-known endpoints for security.txt and exposed configuration files
Example: Missing security.txt contact information
Transport-level checks covering DNS, TLS, and email security configuration
Analyzes DNS configuration for dangling records, missing entries, and subdomain takeover risks
Example: Dangling CNAME pointing to unclaimed cloud service
Checks whether DNSSEC is configured and validates correctly
Example: Domain is not signed with DNSSEC
Validates SSL/TLS certificate chain, expiry dates, and cipher configuration
Example: TLS certificate expires in 12 days
Checks SPF, DKIM, and DMARC records for protection against forged email
Example: Missing DMARC record allows forged email from your domain
Tests Cross-Origin Resource Sharing policy for overly permissive rules
Example: CORS allows any origin to read responses
Repeats the CORS checks against endpoints that need a login, using real credentials
Example: Any origin can read a logged-in user's data
Analyzes HTTP redirect chains for missing HTTPS upgrades and redirect loops
Example: HTTP to HTTPS redirect missing on main domain
Start with a free 14-day Starter trial. Active probing that proves what's actually exploitable, not just a checklist.