Free Web Scanner

Ship secure AI-built apps.

Scan your website in seconds. Find launch-blocking security issues — missing headers, exposed API keys, cookie flags, CORS misconfiguration — before your users do. No account required.

What's included

Two tools. One platform.

Web Scanner

Instant security checks for any web application.

Paste a URL. Get a full security report — TLS health, missing headers, cookie flags, CORS policy, and exposed API keys. No account required.

  • TLS certificate & protocol version
  • Security headers & CSP validation
  • Exposed OpenAI, Anthropic & cloud keys
  • Cookie security flags
Try the scanner →
example.com
✓ Scan complete
B+
Security score
4 issues · 2 need immediate attention
CRITICALMissing Content-Security-Policy header
HIGHOpenAI API key exposed in HTTP response
MEDIUMCookie missing Secure and SameSite flags
LOWHSTS max-age below recommended 1 year
vulnpilot
5,482Total findings
47Unique hosts
19KEV matches
ScorePriorityCVE / Finding
100.0CRITICAL NOWCVE-2021-44228Log4Shell (Apache log4j2)★ KEV
100.0CRITICAL NOWCVE-2023-34362MOVEit SQL Injection★ KEV
99.8CRITICAL NOWCVE-2020-1472Zerologon (Netlogon)★ KEV
23.4MEDIUMCVE-2023-44487HTTP/2 Rapid Reset Attack
11.5LOWN/ASSH Weak Cipher Suites
VulnPilot · Open Source · MIT

Rank vulnerabilities by exploitation, not severity.

Your scanner finds 5,000 findings. VulnPilot identifies the 19 actively being exploited right now — then generates your SOC 2 evidence pack in one command.

  • CISA KEV + FIRST EPSS composite scoring
  • SOC 2 CC7.1 & ISO 27001 evidence
  • Local-only — zero cloud upload
  • Nessus CSV import
View on GitHub →

SSRF-safe scanning

Every scan target is validated against private/internal network ranges before we ever connect. Your infrastructure is never a target.

No scan data leaves your perimeter

VulnPilot runs entirely on your machine — on-premises and VPC deployment available for teams that need it.

Audit-ready evidence

VulnPilot tracks every exception, SLA, and remediation with a full history. One export covers an entire audit cycle.

Open source at the core

VulnPilot is MIT-licensed and auditable. No black-box scoring — see exactly how every finding is prioritized.

Ready to check your next deploy?

Free instant scan — no account, no credit card. Evaluating PatchVex for your team or org instead?