free · passive · no signup

protect yoursite.

scan any site for security misconfigurations — headers, ssl, cookies & cors — in under 10 seconds.

3 free scans per day · Passive scan only · We never attempt to exploit

+65k
scans done
40+
checks run
zero
exploits sent

© 2025–26 flux8labs · passive scan only · not a pentest

+65k

sites scanned

40+

checks per scan

<10s

report in under 10s

free

3 scans/day, no signup

10header rules
9file path checks
5client-side checks
4ssl / tls checks
4cookie checks
2cors checks
coverage

what we
scan for.

every check is passive — we read what a browser can already see, translate it into plain fixes, and keep the scan fully read-only.

01

security headers

02

ssl / tls config

03

cookie security

04

info exposure

05

client-side risks

06

cors & apis

process

three steps
to your score.

paste a public URL. we inspect the surface it exposes, rank the risks, and return a fix list your team can ship.

01

paste a public url

we normalize the URL, follow redirects, and inspect only public responses.

02

we run the checks

headers, tls, cookies, policies, and exposure signals are checked in parallel.

03

read the fix list

you get severity, impact, and exact remediations instead of a wall of findings.

sample output

here's the report
your team can use.

every finding includes severity, business impact, and the exact header or config line to fix it.

62
/ 100
HIGH RISK
2 critical · 1 high
1 medium · 3 passed
findings — example.com
criticalmissing content-security-policy

no csp header — inline scripts and cross-site injections completely unblocked.

🔧Content-Security-Policy: default-src 'self'
highx-frame-options not set

site can be embedded in iframes on any domain — enables clickjacking.

🔧X-Frame-Options: DENY
mediumcookies missing secure flag

3 session cookies found without the secure flag — sent over http.

🔧Set-Cookie: session=...; Secure; HttpOnly; SameSite=Strict
lowreferrer-policy too permissive

full-url referrers may leak sensitive paths and query params to external sites.

🔧Referrer-Policy: strict-origin-when-cross-origin
lowpermissions-policy not locked down

camera, microphone, and geolocation remain available unless explicitly restricted.

🔧Permissions-Policy: camera=(), microphone=(), geolocation=()
passhsts enabled

strict-transport-security is present with a long max-age and preload-ready settings.

passssl certificate valid

let's encrypt certificate — valid for 287 more days. auto-renewal active.

lowreferrer-policy misconfigured
+more findings in your report

passive

ethical by design

passive only.
no tricks.

we use standard requests, never brute-force credentials, and never touch private endpoints. every check is safe to run on a production site.

attack payloads
zero
auth attempts
zero
passive only
100%
no exploits or attack payloads
we only make standard GET requests with a declared user-agent
no auth attempts
we never try passwords, tokens, or exploit known cves
public data only
everything we check is visible to any browser in the world
Flux8Shieldby flux8labs

need help turning
findings into fixes?

flux8labs offers header hardening, TLS cleanup, and remediation support so your team can ship a cleaner site fast.

security review
book a hardening call
also from flux8labs
run the seo audit tool

results are indicative — not a professional penetration test