free · passive · no signup
scan any site for security misconfigurations — headers, ssl, cookies & cors — in under 10 seconds.
© 2025–26 flux8labs · passive scan only · not a pentest
free passive scanner — headers, ssl, cookies & cors. no signup. under 10 seconds.
scans completed
security checks
exploits sent. ever.
© 2025–26 flux8labs · passive analysis only · not a pentest
sites scanned
checks per scan
report in under 10s
3 scans/day, no signup
every check is passive — we read what a browser can already see, translate it into plain fixes, and keep the scan fully read-only.
hsts, csp, x-frame-options, referrer-policy, permissions-policy + 5 more
certificate validity, expiry countdown, https redirect, mixed content
httponly, secure flags, samesite attribute checked on every cookie
exposed .env, .git, wp-config, server version header leakage
inline scripts, sri on cdn assets, eval() usage, unencrypted form actions
wildcard origins, reflected-origin misconfig, credentialed cross-origin requests
paste a public URL. we inspect the surface it exposes, rank the risks, and return a fix list your team can ship.
we normalize the URL, follow redirects, and inspect only public responses.
headers, tls, cookies, policies, and exposure signals are checked in parallel.
you get severity, impact, and exact remediations instead of a wall of findings.
every finding includes severity, business impact, and the exact header or config line to fix it.
no csp header — inline scripts and cross-site injections completely unblocked.
Content-Security-Policy: default-src 'self'site can be embedded in iframes on any domain — enables clickjacking.
X-Frame-Options: DENY3 session cookies found without the secure flag — sent over http.
Set-Cookie: session=...; Secure; HttpOnly; SameSite=Strictfull-url referrers may leak sensitive paths and query params to external sites.
Referrer-Policy: strict-origin-when-cross-origincamera, microphone, and geolocation remain available unless explicitly restricted.
Permissions-Policy: camera=(), microphone=(), geolocation=()strict-transport-security is present with a long max-age and preload-ready settings.
let's encrypt certificate — valid for 287 more days. auto-renewal active.
we use standard requests, never brute-force credentials, and never touch private endpoints. every check is safe to run on a production site.
flux8labs offers header hardening, TLS cleanup, and remediation support so your team can ship a cleaner site fast.
results are indicative — not a professional penetration test