Find your weak spots before hackers do.
17 public modules surface findings before verification. 6 heavy scanners unlock only for a verified owner.
What happens when you press Scan
One workflow, independent layers.
17 public modules maximize findings and coverage before verification. Only 6 heavy scanners require a verified owner. 3 are external engines.
Why this matters
Not a tech person? This is still about you.
Hackers don't choose targets. Robots do.
Most attacks are automated. Bots probe every website on the internet, small ones included. Yours is being tested right now — whether you know it or not.
One leak can cost you the business.
A stolen customer list, a defaced page, a warning in Google — trust takes years to build and one incident to lose. Privacy fines come on top.
You can't fix what you can't see.
Most weak spots are silent: nothing looks broken until it's too late. A scan makes them visible — in plain language, not tech-speak.
Standards-backed deep analysis
Independent scanners. Evidence-backed findings. Clear fixes.
How it works
Three steps. No installs. No signup.
- 1
Paste your address
Type your website address and press Scan. That's all we need from you.
- 2
We run 17 public modules
Maximum findings and coverage arrive before verification. 6 heavy scanners unlock only for a verified owner.
- 3
You get a fix list
Every issue explained in plain words, with a step-by-step fix you can hand to your developer — or paste into AI.
Standards-backed deep analysis
Every finding cites its standard.
Deterministic scanners validate observable signals and link findings to their source standards: OWASP, MITRE, NIST, CIS, GDPR and relevant technical references. Optional AI analysis is separate, deployment-dependent, and never calculates the Security Score.
BoringSec vs free scanners
Free scanners check one thing. One workflow covers more.
SSL Labs, Mozilla Observatory and securityheaders.com are focused tools. BoringSec runs 17 public modules before verification, then 6 verified-owner heavy scanners, including 3 external engines. Continuous monitoring is optional.
| Capability | BoringSec | SSL Labs | Mozilla Observatory | securityheaders.com | ImmuniWeb |
|---|---|---|---|---|---|
| Pre-verification URL modules | 17 public modules | TLS only | Headers + TLS | Headers only | Several tools |
| HTTP security headers (15+) | |||||
| Deep SSL/TLS analysis | |||||
| DNS (SPF, DMARC, DKIM, CAA, DNSSEC) | Partial | ||||
| Exposed secrets and API keys in bundles | |||||
| Known CVEs in your tech stack | Partial | ||||
| Database security (Supabase, Firebase) | |||||
| GDPR and privacy checks | |||||
| Malware and blacklist reputation | Partial | ||||
| Optional continuous monitoring | Paid plan | ||||
| Plain-language and AI-ready fixes | Limited | Limited | Limited | ||
| Reports in 10 languages | |||||
| Unified A++ to F grade | Partial | Partial | Partial | Partial |
We genuinely like these tools and use them too. This comparison shows where each tool is focused. Availability can change.
Public product documentation reviewed Aug 1, 2026. This is not an independent benchmark. ✓ = documented, — = not found in the cited public source, and Partial/Limited = narrower documented scope. BoringSec row labels link to our published evidence.
Two minutes now beats two weeks after a hack.
What's in the report
Every issue explained like a human would.
Open a sample report to see severity, the affected URL or selector, standards citations, captured evidence when available, and a clear explanation. Modules that cannot verify a result are shown honestly instead of being hidden.
- service_role key in bundle.jsCWE-798
- RLS disabled · users, paymentsOWASP A01
- Missing CSP headerCWE-693
- TLS 1.3 · HSTS preloadOK
+ Content-Security-Policy: default-src 'self'; + Strict-Transport-Security: max-age=63072000
Every issue scored on CVSS 4.0 + business impact. Critical / High / Medium / Low / Info, so you know what to fix today vs. queue for next sprint.
Each finding links directly to its source: OWASP article, CWE entry, NIST control, Google doc. Defensible in front of auditors, procurement, and your board.
Optional AI analysis can explain evidence in context when a server-side provider is explicitly configured. Deterministic findings, evidence and scoring remain available without it.
Every finding ships with the exact fix: code diffs, config snippets, or paste-ready prompts for Cursor, Claude Code, Lovable, Bolt, v0, Windsurf.
Deep analysis,
not surface scans.
Each scan runs the checks applicable to the target. The base report shows what passed, failed, or could not be verified. Connected scanners continue independently.
Questions people actually ask
Is the scan safe for my website?
The 17 public modules are bounded and read-only. We do not log in or modify your site. All 6 heavy scanners require a verified owner. 3 are external engines.
Is it really free?
Yes — the scan and a preview of your results are free, no card and no signup. If you want the full detailed report, you'll see clear pricing right on the results page.
I'm not technical. Will I understand the results?
That's exactly who we built this for. Every issue is explained in plain words, and each fix comes as a step-by-step list you can hand to any developer — or paste into AI.
What happens after the scan?
You see the maximum available findings, category counts, severity counts, and coverage right away. The final score stays unavailable until owner verification and all 6 heavy scanners settle.
Still curious? The first look is free, and base results usually start appearing within 60 seconds.