From URL to evidence-backed report
One security scan coordinates independent modules: base results appear first, deeper results follow, and each supported finding includes evidence and a fix path. Here is exactly what happens and why you can trust the result.
Three steps, about a minute
1. Paste a URL
No signup, no agent, no code changes. We scan your live site from the outside — exactly the way an attacker sees it.
2. Scanners stream results
17 bounded public modules maximize findings, category counts, severity counts and coverage before verification. Injection, XSS and Ports wait for owner verification together with 3 external engines.
3. Keep findings now. Grade only verified coverage
Findings and coverage remain useful immediately. The overall score and grade stay N/A until every required category, including Injection, XSS, Ports, Nuclei, ZAP, and Medusa, settles with fully verified coverage. No numeric provisional score is published.
Results stream progressively: the basic report is ready in seconds, heavy results follow after owner verification. Injection, XSS, and Ports run in process. The external Nuclei, OWASP ZAP, and Medusa engines run hardened and are documented in the methodology.
Findings you can trust. Enforced by code, not by promise.
Most scanners inflate severity to look useful. We hard-coded the opposite.
No proof, no alarm
Any critical or high finding that lacks captured evidence is automatically downgraded to medium — and the downgrade is disclosed in the report. This rule is enforced in the scanner code, not in a policy document.
Honest score withholding
If every required category is not fully verified, the overall score and grade stay N/A instead of being quietly padded. Findings, category status, severity counts, and withheld coverage remain visible.
Standards, cited
Every finding links to the standard that defines it: OWASP, CWE, the relevant RFC, MDN. You can verify every claim we make.
Your data stays yours
Cookie values are not stored. Uploaded scan artifacts are reduced to SHA-256 hashes. Scans are bounded, rate-limited and configured for non-destructive checks. Blocked or unavailable modules are reported.
An honest score, documented publicly
After owner verification and fully verified settlement of every required category — including Injection, XSS, Ports, Nuclei, ZAP, and Medusa — the Security Score is a weighted aggregate graded A++ (100) to F (below 40). Until then it is N/A, while findings and coverage remain visible. Any confirmed critical caps an assessable score at 30. AI-built apps also get an assessable Boring Score with leaked keys weighted first. Every weight, cap and rule is public in the docs.
From finding to fix, without leaving your tool
Every finding ships with step-by-step remediation and an AI fix prompt tailored to Cursor, Lovable, Bolt, Claude Code, Replit, v0 or Windsurf. Mechanical fixes come as deterministic autofix templates. And generated workspace rules (.cursorrules, AGENTS.md) teach your assistant to stop introducing the same class of bug. On paid plans, the MCP server runs the whole loop inside your editor.
Where BoringSec fits
vs free single-purpose checkers
SSL Labs grades TLS. securityheaders.com grades headers. Both are excellent — at one thing. BoringSec publishes 17 pre-verification URL modules plus 6 verified-owner heavy scanners (3 external engines): the pre-verification modules report first, while Injection, XSS, Ports, Nuclei, ZAP, and Medusa require a verified owner. Coverage includes secrets in shipped JavaScript, live Supabase/Firebase rule verification, subdomain takeover fingerprints, and client-side skimmer detection.
vs enterprise platforms
Wiz, Rapid7 and Qualys are built for security teams with budgets and onboarding calls. BoringSec is self-serve: results in about a minute, pricing a solo founder can expense without a procurement cycle, and fixes written for the person who will actually ship them.
What only BoringSec does
Built for AI-built apps: a Boring Score weighted for how vibe-coded apps actually fail, fix prompts for Cursor, Lovable, Bolt, Claude Code, Replit, v0 and Windsurf, generated workspace security rules, and an MCP server that puts the whole loop inside your editor.
Tool-by-tool details: all comparisons · why BoringSec · see a sample report
See it on your own site
The fastest way to understand how it works is to run it. Free, no account, about a minute.
Scan your site free