Online · passive scan of your website

I know where your site has weak spots.

Vulscan inspects your domain in seconds and shows where an attacker would strike before you can react. No signup, no install, free.

Passive scanNo signup20+ checks
Enter a domainhttps://
TRY
Scanned domains feed our public counter · no cookies, no IPs. More
What we've seen so far
Our private pipeline maps the web — these numbers grow daily. Here's a live snapshot.
Domains tracked
across TLDs
Passively scanned
full report
Owners alerted to a critical finding
after our outreach
What we check

Over twenty checks your IT should run — but usually doesn't.

We probe your domain with the same methods every attacker starts with. If we find something, we explain it in plain language and suggest a concrete next step.

01
HTTPS & TLS
Cert validity & chain, protocol version, HTTP→HTTPS redirect, HSTS preload.
02
Security headers
CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
03
DNS records
SPF, DMARC, CAA. Email spoofing defence and CA authorisation.
04
Cookies & privacy
Secure, HttpOnly, SameSite attributes on session cookies. GDPR + ePrivacy alignment.
05
Exposed paths
/.git, /.env, /.htpasswd, phpinfo, /.DS_Store and exposed directory listings.
06
WordPress hygiene
Version detection, xmlrpc, user enumeration, exposed debug.log, open wp-admin.
07
Hosting diagnostics
Reverse DNS and hosting provider detection. Context for other checks.
08
security.txt & contact
Presence of the RFC 9116 contact file for vulnerability reports.
09
Info disclosure
Server header, X-Powered-By — exact technology versions leaking in responses.
Specialised audits

Audits tailored to your stack

A generic passive scan isn't always enough. We have four variants with checks tuned to a specific type of site.

What happens if you ignore it

  • 1
    Customer data leak. A GDPR fine can reach 4% of revenue. Reputation damage lasts years.
  • 2
    Domain hijacked for spam. Weak SPF/DMARC — anyone can send email as you.
  • 3
    Search penalty. Google pushes HTTP sites down and warns users away.
  • 4
    Site takeover. An outdated WordPress plugin = admin access in minutes.

Why fix it now

  • A
    Fixes are cheap. Most headers take 15 minutes. An incident takes weeks.
  • B
    We're on your side. No paywalls. If you're stuck, email me — I'll help.
  • C
    EU + NIS2 ready. Built for the NIS2 era. Concrete advice for SMB operators.
  • D
    Continuous watch. Soon: I'll alert you when something changes — for good or bad.

Find out where you're weak. Takes a few seconds.

Passive scan, no intrusive testing. No signup.