Enter your domain: in 30 seconds, we tell you how many API keys, sensitive files and vulnerabilities your site exposes - for free.
The leaks that cost modern websites the most - especially the ones built fast.
.git, .env, SQL backups, directory listings.Secure, HttpOnly, SameSite.Most tools bombard sites with aggressive requests. We read what your server already sends - like a browser - then probe only known weak points, on your own domain, after ownership verification.
We never test a key we find (using it would be unauthorized access). We mask and hash it. Your secrets are never stored in clear text.
That's what makes the audit legal - and trustworthy.
Enter your domain. In seconds, we tell you how many vulnerabilities your site exposes, ranked by severity.
Pay, then prove domain ownership (DNS, file or meta tag - just like Google Search Console).
Every detail + the fixes, the deep analysis (exposed .git/.env…), the PDF, and a copy by email.
The scan is free: you immediately see how many vulnerabilities your site exposes. You only pay to unlock the details and fixes.
For comparison, a manual security audit costs several hundred euros.
.git/.env files…)VAT not applicable (French CGI art. 293 B).
Yes, on your site. That's why we require proof of domain ownership before any active audit. Auditing a site you don't own is illegal - our system prevents it.
No. The audit is non-destructive: GET requests only, no data modified or deleted. To detect injections (SQL, XSS) on your own verified domain, we send harmless test values (a simple marker) into your parameters and watch the response - never a destructive payload (no DROP, no stored content). These injection tests only run after ownership verification.
Nothing. We never test them, we mask them immediately and only store a non-reversible fingerprint. The report never contains your secrets in clear text.
Yes. The free scan reads your site's public pages and tells you how many vulnerabilities it detects, ranked by severity. You only pay to unlock the details, the fixes, the deep analysis and the PDF report.
No. It's an automated audit covering the most frequent and costly vulnerabilities (secrets, configuration, dependencies). It doesn't replace a thorough manual penetration test, but it catches the essentials in a minute.