SecScanner is a website security scanner for public-facing sites. It runs more than 60 automated checks on a URL and returns a detailed report with exact fix instructions for each finding. The service is built for situations where a quick scan is needed without setup, since one URL is enough to start and no agents, plugins, or access tokens are required.
Its checks cover TLS/HTTPS configuration, security headers, DNS, cookies, CORS, exposed endpoints, and page content. The page highlights TLS certificate validity, cipher strength, protocol version, OCSP stapling, and redirect behavior; headers such as CSP, HSTS, X-Frame-Options, and Permissions-Policy; SPF, DKIM, and DMARC validation for email security; cookie attributes including HttpOnly, Secure, and SameSite; and network exposure such as open ports and reachable admin paths. It also lists checks for subdomain takeover and vulnerable JavaScript libraries. Each issue is paired with specific remediation guidance, and the product includes continuous monitoring with daily or weekly scans plus email or Slack alerts when something regresses.
SecScanner also maps scan results to SOC 2, PCI DSS, HIPAA, GDPR, ISO 27001, and NIS2, and it can export a PDF audit report for sharing with customers or auditors. The site says scans are free and complete in 1 to 3 minutes, with results in seconds. A free plan is listed at $0 forever with unlimited scans, 24 free security checks, TLS/HTTPS validation, security headers analysis, PDF reports, and email support. Paid monthly and annual plans add all 62 security checks, daily or weekly monitoring, email, Slack, and webhook alerts, compliance reports, API access, and priority support.
In the Application security & vulnerability scanning space, SecScanner takes a focused approach. It focuses on identifying and reporting website security vulnerabilities quickly and efficiently. SecScanner is a B2B product aimed at website owners. A free plan is available. It ships for the web.
SecScanner first shipped in 2025. Key capabilities include security scanning, TLS/HTTPS checks, and header analysis.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do