SSL / TLS
Certificate validity, expiry, protocol version and HSTS enforcement.
Security Headers
CSP, X-Frame-Options, HSTS, Referrer-Policy and Permissions-Policy.
OWASP Top 10
Injection points, XSS vectors, broken auth and misconfigurations.
DNS & Network
DNS records, open ports, subdomain exposure and network risks.
API Endpoints
Exposed REST, GraphQL and unauthenticated API access detection.
Exposed Files
Backup files, .env exposure, admin panels and sensitive paths.
WAF Detection
Identifies Web Application Firewalls and their bypass surface.
CMS & Stack
Technology fingerprinting: framework, server, CDN and versions.
JavaScript Analysis
Client-side secrets, hardcoded keys and insecure third-party scripts.