Skip to content

Only scan sites you own or have permission to test.

No account or credit card required for the free scan.

Scan report

yourapp.com

Sample

Slop Score

0/100

Needs work. Based on the ranked findings from this scan.

Severity mix
Share of findings by severity for this scan only.
10 findings
48s
10
12

What needs attention

Select a finding to review its evidence and impact.

Evidence

Found in /_next/static/chunks/checkout.js: sk_live_****

Why it matters

Anyone can download the bundle, recover the key, and attempt unauthorized payment API calls.

Join free to save results and keep scanning. Paid plans add the full report and monitoring.

Join for free

Fix prompts

Copy fix prompts straight into your coding tool.

When the scan finds something, copy the evidence-backed prompt into Cursor or whatever you're already using. Or connect MCP to pull findings in your editor.

  • Cursor
  • Claude Code
  • GitHub Copilot
  • Windsurf
  • Gemini
  • Cline
  • Replit
  • v0
  • Amp
  • Zed
  • Bolt
  • Lovable
  • StackBlitz

What gets checked

Seven areas of the public site, one scan.

Security, search, performance, accessibility, legal signals, runtime, and infrastructure — all checked together, including known vulnerabilities.

Interactive view of seven website areas checked by SlaySlop

Catch known vulnerabilities, exposed secrets, weak headers, and public backend misconfigurations.

What you get

Not just a finding — the reason it matters.

Each finding shows its impact, the evidence that triggered it, and whether a rescan clears it.

Interactive report view with findings, evidence, and rescan progress

The biggest risks show up first.

Domain insights

More than just the page.

DNS, TLS, headers, mail config, and tech stack sit right next to the ranked findings on every scan.

Security posture

TLS certificates, HTTP security headers, WAF signals, HSTS, and public block-list reputation.

Server and DNS

DNS records, DNSSEC, WHOIS, mail configuration, redirects, ports, and server location.

Content surface

Tech stack fingerprints, robots.txt, sitemaps, cookies, social tags, and linked pages.

Sample insight feed

What a scan surfaces for yourapp.com

SSL certificate
Clear

Valid for yourapp.com. Expires in 47 days.

Technology stack
Clear

Next.js and Vercel fingerprints on the public HTML.

Mail configuration
Needs review

SPF is present. DMARC policy is missing.

Firewall / WAF
Clear

Cloudflare headers detected on the origin response.

Insight checks included in a scan

DNSSSL certificateHTTP security headersFirewall / WAFWHOISMail configurationTechnology stackrobots.txtBlock listsSubdomainsHSTSCookies
DNSSSL certificateHTTP security headersFirewall / WAFWHOISMail configurationTechnology stackrobots.txtBlock listsSubdomainsHSTSCookies
DNSSSL certificateHTTP security headersFirewall / WAFWHOISMail configurationTechnology stackrobots.txtBlock listsSubdomainsHSTSCookies
DNSSSL certificateHTTP security headersFirewall / WAFWHOISMail configurationTechnology stackrobots.txtBlock listsSubdomainsHSTSCookies

Find it. Fix it. Confirm it's gone.

Copy the evidence-backed prompt, apply the fix, then scan again to verify.

Evidence captured

The exact page, response, and impact that triggered the finding.

Missing Content-Security-Policy on 12 of 12 scanned pages.

Fix prompt ready

Take the finding and evidence straight to Cursor or another coding agent.

Add CSP to the 12 scanned pages on yourapp.com. Start in report-only mode, preserve observed script origins, then enforce with nonces.

Rescan confirms it's gone

A follow-up scan checks whether the issue still appears.

Finding cleared on re-scan

Live-site monitoring

New vulnerabilities show up after launch too.

Scheduled rescans catch new issues. Uptime probes run around the clock.

Always-on uptime checks

Your availability probes run around the clock at the interval you choose. Three failed checks open an incident, and three successful checks close it.

Scanning 24/7

Explore monitoring

Common questions

What the free scan covers, how the Free plan works, and when billing starts.

Not sure whether you can scan a site? Ask about scan eligibility

Your site is probably leaking something.

Run a free scan and find out. Join free to keep the results.