WebsiteScanner runs deep security scans on your website and delivers plain-English AI reports that tell you exactly what to fix and why it matters.
No account needed · 6 passive checks · Results in ~10 seconds
No account needed · SPF, DKIM, DMARC, MX, Blacklist, BIMI · Results in seconds
Checking DNS records...
Checking SPF record
Checking DKIM selectors
Checking DMARC policy
Checking MX records
Checking blacklists
Checking BIMI
We run the same checks a professional penetration tester would — automatically, on demand.
Validates certificate chain, expiry, protocol strength & cipher suites.
Checks CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy & more.
Scans top 20 ports for exposed databases, admin panels & legacy services.
Tests cross-origin resource sharing policy for misconfigurations that could expose your data.
Checks CSRF protection, username enumeration, rate limiting & form security.
WPScan for WordPress/WooCommerce, Droopescan for Drupal, Nikto for all platforms.
Gobuster finds hidden paths, backup files & admin panels using common wordlists.
Verifies email authentication DNS records to prevent spoofing & phishing.
Scans pages for malware, phishing, tech stack & certificate analysis via Cloudflare Radar.
Checks Google's real-time threat database for malware & social engineering warnings.
Checks if your domain appears in known data breaches. Professional+ plans.
Executive summary for business owners, written by Claude AI, explaining risks in plain language with Australian Privacy Act context.
Detailed remediation report for developers with specific commands, config changes & CVE references.
AI identifies realistic multi-step attack scenarios combining your findings into worst-case impact assessments.
Our comprehensive email health check analyses your DNS records and tests your mail server's live SMTP configuration.
Score out of 100 with letter grade
Instant A-F rating for your email security posture.
Check history & trend tracking
Track improvements over time as you fix issues.
AI-powered fix instructions
Step-by-step guidance written in plain English. Pro+ plans.
PDF report download
Share results with your team or IT provider. Pro+ plans.
SMTP server live testing
Real connection tests via our dedicated Kali security server.
Don't just find problems — prove you fixed them. Track, compare, and demonstrate your security improvements.
Up to 12 months of scan history. Compare scores between scans to track improvement.
Visual score tracking shows your security posture improving as you fix findings.
Re-scan after fixes to prove remediation. Show stakeholders measurable progress.
No agents to install, no complex setup. Just results.
Enter the domain you want to audit. We verify ownership with a simple DNS record.
Choose your plan and kick off the scan. Our automated tools check everything in the background — no waiting around.
Receive a prioritised list of findings plus two AI-written reports — one for your team, one for your boss or client.
Every plan includes AI-generated reports. No hidden fees.
Essential checks for small sites
$59/mo
Scanning
Threat Intel
Reports
Up to 3 domains · 30-day history
Deep scans for growing businesses
$129/mo
Scanning
Threat Intel
Reports
Email Health · Up to 5 domains · 12-month history
Full coverage for agencies & teams
$299/mo
Scanning
Threat Intel
Reports
Unlimited domains · Scheduled scans · Unlimited history
All prices in AUD. Annual plans available at a discount. View full pricing
Join other website owners protecting their sites with WebsiteScanner.
Start Your Free AuditWe use cookies
We use essential cookies to keep your session secure. Optional cookies help us improve your experience. Privacy Policy · Cookie Policy
Choose which cookies you accept.
Session authentication, CSRF protection, and Livewire functionality. The site cannot function without these.
laravel_session, XSRF-TOKEN
Helps us understand how the service is used so we can improve it. No personal data is shared with third parties.
_ga, _ga_R581LZLTQX (Google Analytics 4)
Used to deliver relevant promotional content. We do not sell your data to third parties.
No marketing cookies currently set.