240+ provera na jednom mestu

Web Security Scanner

Bezbednost, SEO, performanse, GDPR, email, WHOIS, tech stack — 240+ provera besplatno

Brzi sken: 21 modul (167+ provera) bez verifikacije. Puni sken: dodatnih 10 modula (74+ provera) — zahteva dokaz vlasnistva.
Data Protection Badge
Data Protection PII hashovan (SHA-256) · ZZPL uskladjen · Audit log · Enkriptovani backup-ovi PII hashed (SHA-256) · ZZPL compliant · Audit log · Encrypted backups
Inicijalizacija... 0%
💻 Informacije o vasem sistemu
Ovi podaci se prikazuju lokalno u vasem pregledacu. Nista se ne salje niti cuva na nasem serveru. This data is displayed locally in your browser. Nothing is sent to or stored on our server.
Data Protection Badge
Data Protection Vasi podaci su zasticeni: hashovanje, audit log, enkriptovani backup-ovi Your data is protected: hashing, audit log, encrypted backups
🔒
Brzi javni sken — 20 provera zavrseno Quick public scan — 20 checks complete Prikazano je sve sto je bezbedno bez potvrde vlasnistva. Da otkljucate dodatnih 10 provera (osetljivi fajlovi, admin paneli, ranjivosti, otvoreni portovi, dependency CVE) — potvrdite da ste vlasnik domena. Skener tada nece poslati nijedan probe ka privatnoj infrastrukturi sajta dok se vlasnistvo ne dokaze. Showing everything that's safe to check without ownership proof. To unlock 10 additional checks (sensitive files, admin panels, vulnerabilities, open ports, dependency CVEs) — verify you are the domain owner. The scanner will not send a single probe to private infrastructure until ownership is proven.

Verifikuj vlasnistvo domena

Zasto trazimo verifikaciju? Why do we require verification? Scanner otkriva specificne ranjivosti sajta - URL-ove izlozenih fajlova, admin stranice, detalje ranjivosti, reprodukcione korake. Ove informacije su korisne vlasniku sajta koji hoce da popravi probleme, ali bi u rukama napadaca bile exploit cheat sheet. Zato za svaku takvu stavku trazimo da dokazete da ste vi vlasnik domena koji skenirate. The scanner uncovers specific site vulnerabilities — exposed file URLs, admin panel paths, vulnerability details, reproduction steps. That information is useful for the site owner who wants to fix the problems, but would be an exploit cheat sheet in an attacker's hands. So for every sensitive finding, we require you to prove you are the owner of the domain you are scanning.

Nakon verifikacije dobijate After verification you get

  • Pun spisak izlozenih fajlova (.env, .git, backup dumpovi, phpMyAdmin, wp-config.php) Full list of exposed files (.env, .git, backup dumps, phpMyAdmin, wp-config.php)
  • Admin panel URL-ove i njihove status kodove Admin panel URLs and their status codes
  • Detaljne opise ranjivosti sa severity ocenama i preporukama za popravku Detailed vulnerability descriptions with severity ratings and fix recommendations
  • Reprodukcione korake za pronadjene probleme (za tvoje devops/security kolege) Reproduction steps for the findings (for your devops/security team)
  • 30-dnevni otkljucan pristup za bilo koji buduci scan istog domena sa iste IP adrese 30-day unlocked access to any future scan of the same domain from the same IP

Kada potvrdite odgovornost, izaberite jednu od 3 metode verifikacije: Once you accept responsibility, pick one of the 3 verification methods:

Sta proveravamo

240+ provera u 4 kategorije
SSL/TLS sertifikati i enkripcija
HTTP sigurnosni headeri (7 provera)
DNS bezbednost (SPF/DMARC/DNSSEC)
Detekcija ranjivosti (SQL, XSS, CSRF)
Osetljivi fajlovi, portovi, CORS
WHOIS informacije o domenu
Email bezbednost (MTA-STS, DANE, TLS-RPT)
Mozilla Observatory ocena
Tech stack detekcija
Certificate Transparency logovi
Cookie bezbednost (Secure, HttpOnly, SameSite)
Redirect lanci i petlje
CMS detekcija (WordPress, Joomla, Drupal...)
JWT analiza (alg:none, slabi kljucevi)
Information disclosure (verzije, debug)
.well-known endpoint-ovi (8 IETF/W3C)
JavaScript bezbednost (inline, SRI, source maps)
WHOIS informacije i starost domena
WPScan-lite (plugini, korisnici, xmlrpc)
Subdomain discovery (CT logovi)
Subdomain takeover detekcija (22 SaaS)
SAFE = bez verifikacije (20 modula). FULL = zahteva vlasnistvo (10 modula)
Saznajte vise →
Title, description, viewport
Open Graph i Twitter Cards
Heading struktura (H1-H6)
Sitemap.xml i robots.txt
Strukturirani podaci (Schema.org)
Canonical URL
Hreflang / lang atribut
Alt tekst za slike
Robots meta direktive
Saznajte vise →
TTFB (vreme odgovora servera)
Kompresija (Gzip/Brotli)
Cache headeri i HTTP/2
Lazy loading i optimizacija slika
Velicina stranice i resursa
Minifikacija CSS/JS
HTTP/2 i HTTP/3 podrska
Pristupacnost (ARIA, forme, headings)
Tabindex i fokus redosled
Saznajte vise →
Privacy Policy detekcija
Cookie consent mehanizam
Third-party trackeri (GA, FB, Hotjar)
HTTPS za podatke korisnika
Forme i enkripcija podataka
Uslovi koriscenja
Third-party cookies analiza
Saznajte vise →