Inspect HTTPS and headers
Review HSTS, CSP, frame protection, and other browser security controls.
Security and secrets
Headers, certificates, known vulnerabilities, client-bundle secrets, and public threat intelligence are checked in one run.
Review HSTS, CSP, frame protection, and other browser security controls.
Client bundles and responses are checked for exposed keys, tokens, and credentials.
Known vulnerability and misconfiguration templates test the public attack surface.
Evidence and severity separate urgent leaks from lower-risk hardening work.
See the exact response state behind every missing or weak control.
Sensitive findings are gated and presented without publishing full credential values.
Certificate and connection findings sit beside DNS and server evidence.
Scan history makes it clear when a security regression appeared.