Vulscan inspects your domain in seconds and shows where an attacker would strike before you can react. No signup, no install, free.
We probe your domain with the same methods every attacker starts with. If we find something, we explain it in plain language and suggest a concrete next step.
A generic passive scan isn't always enough. We have four variants with checks tuned to a specific type of site.
General audit of any domain. 20+ checks — TLS, headers, DNS, exposed files, WordPress.
15+ WordPress-specific checks — xmlrpc, debug.log, user enumeration, exposed wp-config.
Cookies, GDPR, payment redirect, mixed content. WooCommerce, Magento, PrestaShop and custom builds.
Deep test of TLS, HSTS, CSP and 18 more security headers.
Passive scan, no intrusive testing. No signup.