5,200+ CZ domains scanned · 365 owners notified of a critical finding

Find out where your site has weaknesses. In 30 seconds.

One input, 20+ checks — TLS, headers, exposed files, DNS, WordPress. Within half a minute you'll see results and you can email yourself a PDF report with concrete remediation steps.

Passive scan · no signup · results in 30 seconds
https://
Scan takes 30 seconds. You can request the PDF report with a button on the results page.

How it works

3 steps · 30 seconds
01

Enter your domain

No signup, just the URL. No email — we ask for that only when you request the PDF report.

02

We scan 20+ things

Passively. TLS, security headers, DNS (SPF/DMARC), exposed files, CMS versions, open ports.

03

Results and PDF report

You'll see all findings right on the site. Request the PDF report via the button — every finding has an explanation, impact and concrete remediation step.

What we specifically look for

We probe your domain with the same methods every attacker starts with. If we find something, we explain it for non-experts too.

Headerscritical

Missing Content-Security-Policy

Without CSP any XSS payload can run third-party code at your customers.

Content-Security-Policy: (not present)
Exposedcritical

Publicly accessible /.git

An attacker downloads your entire source. It may contain database credentials or API keys.

GET /.git/HEAD → 200 OK
TLSwarning

TLS 1.0 still enabled

An outdated protocol with known weaknesses, and a PCI-DSS compliance issue.

openssl s_client -tls1 → handshake OK
DNSwarning

DMARC policy = none

Anyone can send emails as your domain. Spam reaches your clients.

_dmarc: v=DMARC1; p=none
WordPresswarning

WordPress 6.2 (outdated)

4 vulnerabilities have been patched since your version. Core auto-updates are probably disabled.

generator: WordPress 6.2
30,255
Domains tracked
5,185
Scanned this month
365
Owners alerted to a critical finding
About Vulscan

We look for the same weaknesses an attacker would spot first — not hypothetical textbook vulnerabilities. If we find something, we tell you concretely what to do about it.

01
Passive scan
No invasive tests. We behave like a visitor — your site won't notice we're there.
02
European context
We know local hostings, CMSes and registrars. Recommendations are concrete, not generic.
03
Real help
If you don't understand a finding, write us — a human replies, not a bot.

Frequently asked questions

Is the scan safe? Won't it damage the site?+
Yes. The scan is passive — it behaves like an ordinary visitor. We don't try exploits, don't crack passwords, don't send invasive payloads. The site won't notice we're there.
What do you do with the data? Where do results go?+
You'll see the results right on the site and can then email yourself the PDF report with one click. We keep your email so we can alert you if a new serious finding appears on your domain. You can unsubscribe at any time.
What if you find a critical problem?+
You'll get a report where every problem is explained with a concrete remediation step. Most things your webmaster can handle. If not, write us — we're happy to take a look.
Does it cost money? What's the catch?+
A one-off scan is free.
Who runs this?+
Vulscan is run by a European team with experience in penetration testing and infrastructure management. We focus on web security across the EU — we know local hostings, CMSes and registrars, so recommendations are concrete.

Scanning takes 30 seconds. The fix usually 15 minutes.

Enter a domain, look at the results, and email yourself a PDF report showing where your site currently has open doors — one click.

https://
Scan takes 30 seconds. You can request the PDF report with a button on the results page.
or download a sample PDF report · badexample.vulscan.cz