Comprehensive website vulnerability scanner with threat intelligence and CVE search. Check your site against OWASP, ISO 27001, CIS, and NIST standards โ for free.
Each module runs independently and maps findings to industry compliance frameworks.
Certificate validity, chain trust, protocol version, cipher strength, expiry warnings, HSTS enforcement.
OWASP A02 NIST SC-8CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and 4 more critical headers.
OWASP A05 ISO 27001A, AAAA, MX, TXT, NS records. SPF/DKIM/DMARC validation. DNSSEC checking. Mail security assessment.
NIST SC-20HttpOnly, Secure, SameSite flags. Cookie scope analysis. Session management assessment.
OWASP A07 CIS 16.9Origin policy testing. Wildcard detection. Credential exposure risks. Pre-flight configuration validation.
OWASP A01Common service ports (20+). Unexpected open port detection. Service identification. Risk classification per port.
NIST CM-7 CIS 9.1Identify web server, CMS, frameworks, CDNs, analytics tools. Known vulnerability mapping for detected tech.
OWASP A06Sensitive path exposure in robots.txt. Admin panel detection. Backup file discovery. Information leakage.
OWASP A01Weighted score across all modules. Letter grade (A-F). Severity distribution. Priority remediation order.
ISO 27001 NIST RA-5Live RSS feeds from major security sources. CISA alerts, NIST bulletins, vendor advisories. Searchable, categorised, timestamped.
Search the NVD (National Vulnerability Database) for CVEs by keyword, product, or vendor. CVSS scores, severity, affected versions, references.
Every scan is stored locally in SQLite. Track your security posture over time. Compare scores across scans. Export results.
Each finding maps to specific OWASP, ISO 27001, CIS, and NIST controls. Generate compliance-ready reports for auditors.
Free, no signup required. Enter a URL and get a full security report in under 30 seconds.
Part of the Sparrofox product suite