← Home

Full list of checks

What the service actually checks: a free express check and a paid deep check. For each group, why it matters and which checks are included.

Free check

T1

Website security 18

Security headers (CSP, X-Frame-Options), mixed content, external scripts, technology fingerprint, malware signals, login panels, service files (robots/sitemap/security.txt).

T1-AUTH-01 Login panels (admin/wp-admin/bitrix)
T1-AUTH-02 Basic auth (WWW-Authenticate)
T1-AUTH-03 JWT alg=none (passive)
T1-CFG-01 Verbose application errors
T1-CNT-01 Mixed content
T1-CNT-02 External JS resources
T1-CNT-03 Outdated JS libraries
T1-CNT-04 Forms on HTTP or third-party domains
T1-CNT-05 Technology fingerprint
T1-CNT-06 Malware signals on the homepage
T1-CNT-07 External JS without SRI
T1-CNT-08 robots.txt / sitemap.xml
T1-CNT-09 security.txt (RFC 9116)
T1-HDR-01 Security response headers
T1-HDR-02 Set-Cookie security flags
T1-HDR-03 Version disclosure in headers
T1-HDR-04 CORS: Access-Control-Allow-Origin
T1-HDR-05 Cache-Control: authorized responses

TLS and HTTPS 5

Connection encryption and certificates: protocols and ciphers, certificate, HSTS, OCSP stapling, forced HTTPS redirect.

T1-CNT-10 HTTP redirect to HTTPS
T1-TLS-01 Certificate
T1-TLS-02 Protocols and ciphers
T1-TLS-03 HSTS
T1-TLS-04 Compression, OCSP, SCT

Email and DNS 13

Protection against email spoofing from your domain and mail server settings: SPF, DMARC, DKIM, MTA-STS, TLS-RPT, DNSSEC, CAA, PTR, TLSA, BIMI.

T1-DNS-01 SPF: Sender Policy Framework
T1-DNS-02 DMARC
T1-DNS-03 DKIM
T1-DNS-04 DNSSEC
T1-DNS-05 CAA
T1-DNS-06 MTA-STS
T1-DNS-07 BIMI
T1-DNS-08 AXFR
T1-DNS-09 Wildcard
T1-DNS-10 AAAA
T1-DNS-11 PTR
T1-DNS-12 TLSA
T1-DNS-13 TLS-RPT

Open-source intelligence 8

What is known about you from public sources: lookalike domains, open cloud storage, leaks in public code, public email addresses, IP neighbors, subdomains from certificate transparency (CT) logs.

T1-OSINT-01 Typosquatting: lookalike domains
T1-OSINT-02 Public email addresses
T1-OSINT-03 Open cloud buckets
T1-OSINT-04 Domain mentions in public lists
T1-OSINT-05 IP neighbors (shared hosting)
T1-OSINT-06 Historical URLs with sensitive markers
T1-OSINT-07 Wildcard certificates (CT logs)
T1-SUB-01 Names in CT logs

Reputation 2

Whether the domain or IP is listed in blacklists and threat databases: Google Web Risk, Spamhaus.

T1-REP-02 Google Web Risk Lookup
T1-REP-03 RBL: Spamhaus ZEN (SBL/XBL/PBL)

Domain registration 1

Registration data: registrar, domain expiration date — a sign of a new or abandoned domain.

T1-WHO-01 Registrar and domain data

AI/ML supply chain 4

Exposed AI/ML components: MLflow/Jupyter/TensorBoard panels, LLM proxies (Ollama/OpenAI), keys in JS bundles, publicly accessible ML weights.

T1-AI-01 AI supply chain: ML panels (MLflow/Jupyter/TensorBoard)
T1-AI-02 AI supply chain: LLM proxies (Ollama/OpenAI)
T1-AI-03 AI supply chain: keys in JS bundles
T1-AI-04 AI supply chain: publicly accessible ML weights

Supply chain 3

Leaks in configs and dependencies: exposed .env/.npmrc/.git, lockfiles, package panels (Nexus/Artifactory).

T1-SUP-01 Supply chain: config leaks (.env/.npmrc/.git)
T1-SUP-02 Supply chain: lockfiles (package-lock/yarn/pnpm)
T1-SUP-03 Supply chain: package panels (Nexus/Artifactory/Verdaccio)

Deep check

T2

WordPress 1

Deep WordPress check: versions, plugins, themes, and known vulnerabilities.

T2-CMS-01 WordPress (wpprobe)

CMS: Joomla, Drupal, Bitrix 3

Versions and common vulnerabilities of popular CMS platforms.

T2-CMS-02 Joomla
T2-CMS-03 Drupal
T2-CMS-04 1C-Bitrix

Email (deeper) 3

Mail servers: STARTTLS encryption, open relay, mailbox enumeration (VRFY/EXPN).

T2-MAIL-01 STARTTLS on MX
T2-MAIL-02 Open relay
T2-MAIL-03 VRFY/EXPN

Ports and services 3

Which ports and network services are open to the internet, with banner versions and IPv6 availability.

T2-NET-01 Port scan: key external perimeter ports (web, email, databases, admin panels, monitoring)
T2-NET-02 IPv6 availability (optional)
T2-NET-03 Service versions from banners

Secrets and metadata 3

Exposed secrets in JS, source maps, and public document metadata.

T2-OSINT-01 Document metadata
T2-SEC-01 Exposed secrets in JS
T2-SEC-02 Source maps

Subdomains 3

Discovered subdomains (dev/test/stage), subdomain takeover risk, and similar subdomains.

T2-SUB-02 Subdomains (dev/test/stage)
T2-SUB-03 Subdomain takeover
T2-SUB-04 Subdomain permutations

Risky services 8

Exposed services and their vulnerabilities: open relay, public SNMP, open DNS resolver, NTP, anonymous FTP/SMB access, NFS, versions → CVE.

T2-SVC-01 Risky exposed services
T2-SVC-02 Versions → CVE (OSV + KEV)
T2-SVC-03 Anonymous SMB session
T2-SVC-04 SNMP community public
T2-SVC-05 Open DNS resolver
T2-SVC-06 NTP monlist
T2-SVC-07 FTP anonymous
T2-SVC-08 NFS exports

Web security (deeper) 11

Service paths (.git/.env), HTTP methods, CORS, WebDAV, virtual hosts, endpoint crawling, hidden parameters, admin panels, directory listing, and API documentation.

T2-WEB-01 Service paths (.git/.env)
T2-WEB-02 HTTP methods
T2-WEB-03 CORS
T2-WEB-06 WAF detection (passive)
T2-WEB-08 WebDAV (OPTIONS + Allow)
T2-WEB-09 vhost
T2-WEB-11 Endpoint crawling
T2-WEB-12 Hidden parameters
T2-WEB-13 Admin panels
T2-WEB-14 Directory listing
T2-WEB-16 API documentation

→ Home