🔒 AI-Powered Security Audits

Know your website's security vulnerabilities before hackers do

Free instant website security audit and email health check (SPF / DKIM / DMARC). WebsiteScanner runs deep scans and delivers plain-English AI reports — exactly what to fix and why it matters.

No account needed · 6 passive checks · Results in ~10 seconds

SSL/TLS Security Headers Port Scanning CMS Vulnerabilities Email Security Threat Intelligence AI Reports PDF Export
Features

Everything your website needs to stay secure

We run the same checks a professional penetration tester would — automatically, on demand.

SSL/TLS Certificate

Validates certificate chain, expiry, protocol strength & cipher suites.

Security Headers

Checks CSP, HSTS, X-Frame-Options, X-Content-Type, Referrer-Policy & more.

Port Scan

Scans top 20 ports for exposed databases, admin panels & legacy services.

CORS Configuration

Tests cross-origin resource sharing for misconfigurations that could expose your data.

Login Page Audit

Checks CSRF protection, username enumeration, rate limiting & form security.

CMS Vulnerability Scan

WordPress, Joomla, Drupal — known vulnerabilities, exposed admin paths, plugin/theme versions.

Directory Discovery

Finds hidden paths, backup files & admin panels exposed to the public internet.

Email Security

Verifies SPF / DMARC / DKIM DNS records to prevent spoofing & phishing.

Cloudflare URL Scanner

Scans pages for malware, phishing, tech stack & certificate analysis via Cloudflare Radar.

Google Safe Browsing

Checks Google's real-time threat database for malware & social engineering warnings.

HIBP Breach Database

Checks if your domain appears in known data breaches. Professional+ plans.

Email health

Is your email configuration protecting you from spoofing?

Our comprehensive email health check analyses your DNS records and tests your mail server's live SMTP configuration.

6

DNS Record Checks

SPF
DKIM
DMARC
MX Records
Blacklist
BIMI
7

Live SMTP Server Tests

SMTP Ports
Server Banner
STARTTLS
TLS Certificate
Open Relay
MTA-STS
DANE/TLSA

What you get

Score out of 100 with letter grade
Instant A–F rating for your email security posture.
Check history & trend tracking
Track improvements over time as you fix issues.
AI-powered fix instructions
Step-by-step guidance in plain English. Pro+ plans.
PDF report download
Share results with your team or IT provider. Pro+ plans.
SMTP server live testing
Real connection tests via our dedicated Kali security server.
Check Your Email Health
Track your progress

Watch your security score improve over time

Don't just find problems — prove you fixed them. Track, compare, and demonstrate your security improvements.

Scan History

Up to 12 months of scan history. Compare scores between scans to track improvement.

Score Trends

Visual score tracking shows your security posture improving as you fix findings.

Before & After

Re-scan after fixes to prove remediation. Show stakeholders measurable progress.

How it works

Up and running in minutes

No agents to install, no complex setup. Just results.

1

Enter your domain

No agents, no installs. We work against your public-facing site.

2

We run 20+ checks

SSL, headers, ports, DNS, email auth, threat intel — all in parallel.

3

Get fix instructions

AI writes plain-English guidance with exact steps and severity.

FAQ

Frequently asked questions

Is the WebsiteScanner.ai security audit really free?

Yes. The free instant scan runs around 15 passive checks — SSL/TLS, security headers, open ports, DNS, email authentication, threat intelligence — against any public domain in roughly 10 seconds. No account or payment required. Paid Starter plans add active vulnerability testing, scheduled scans, and AI-generated remediation reports.

What does the website security audit check?

SSL/TLS certificate validity and protocol strength, HTTPS enforcement, HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy), open port exposure, CMS vulnerabilities (WordPress, Joomla, Drupal), directory discovery, email authentication (SPF, DKIM, DMARC, BIMI), DNSSEC, and threat-intelligence feeds (Cloudflare URL Scanner, Google Safe Browsing, HIBP).

How does the email health check work?

We query the live DNS records for SPF, DKIM, DMARC, MX, and BIMI, and run live SMTP tests (port connectivity, server banner, STARTTLS, TLS certificate, open relay, MTA-STS, DANE/TLSA) on Professional and Enterprise plans. Results include an A–F grade and step-by-step fix instructions.

Do I need to install anything to scan my site?

No. WebsiteScanner runs entirely against your public-facing site from our scanner — no agents, no plugins, no DNS changes.

Will the scan harm my website?

The free passive scan only reads publicly available signals (DNS records, headers, certificate info) — it is read-only and indistinguishable from normal traffic. Active vulnerability tests on paid plans run at a controlled rate well below typical pen-test thresholds.

Can I scan a website I do not own?

No. You must verify domain ownership before any active scan can run. The free passive scan is rate-limited and only inspects information already exposed to the public internet.

What does an AI-generated security report include?

Two versions — a plain-English report aimed at the business owner (what the issue means and why it matters) and a technical remediation report aimed at a developer (specific config changes, code examples, CVE references, severity ranking).

Ready to find out what attackers already know about your site?

Join thousands of website owners protecting their sites with WebsiteScanner.

Start Your Free Audit

We use cookies

We use essential cookies to keep your session secure. Optional cookies help us improve your experience. Privacy Policy · Cookie Policy

Cookie Preferences

Choose which cookies you accept.

Strictly Necessary Required

Session authentication, CSRF protection, and Livewire functionality. The site cannot function without these.

laravel_session, XSRF-TOKEN

Analytics

Helps us understand how the service is used so we can improve it. No personal data is shared with third parties.

_ga, _ga_R581LZLTQX (Google Analytics 4)

Marketing

Used to deliver relevant promotional content. We do not sell your data to third parties.

No marketing cookies currently set.

View Cookie Policy