Website security scanner for teams & agencies

Know your security score
in seconds.

Scan any website and get an instant A–F security grade. Export branded PDF reports, monitor client sites daily, and get alerted the moment something breaks.

No account needed to scan · Sign up free to save history & monitor →

75+ security checks
No signup required
Results in seconds
We never store your page content
75+
Security checks
15
Scan categories
<5s
Average scan time
A–F
Instant security grade

One scanner, many workflows

Whether you're auditing your own site or managing dozens of client sites.

Scan any site

Paste a URL — yours, a client's, or a prospect's — and get a full security audit in seconds. No setup required.

Send branded reports

Export white-labeled PDF reports with your logo. Perfect for client deliverables and security reviews.

Monitor & alert

Track sites daily and get notified the moment a grade drops. Stay ahead of certificate expirations and config drift.

How it works

A full security audit in three steps — no installation, no setup.

STEP 1

Enter any URL

Paste any website URL — yours, a competitor's, or a client's. No account needed to start.

STEP 2

Get your security grade

In seconds you get a full A–F grade, score breakdown, and a detailed list of every finding with recommended fixes.

STEP 3

Fix issues & monitor

Follow the fix guidance to improve your grade. Set up monitoring so you're alerted the moment something breaks.

Fix service

Found issues you can't fix yourself?

WebSentry tells you exactly what's broken. But implementing security headers, fixing CSP policies, hardening TLS config, and patching library vulnerabilities takes real dev work.

WebSentry offers a dedicated remediation service. We take your report and fix everything, end to end.

Security headers & CSP
Correctly configured, not just present
SSL / TLS hardening
HSTS, certificate chain, TLS version
Vulnerable library updates
Patch or replace flagged JS dependencies
Cookie & CORS fixes
Secure, HttpOnly, SameSite — done right
Request a fix →

We'll review your report and send a quote.

What the report covers

75+ security checks across 15 categories, scanned in seconds.

SSL / TLS

4 checks

Certificate validity, HSTS enforcement, TLS version, and HTTPS availability.

Security Headers

7 checks

CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.

CSP Deep Analysis

8 checks

unsafe-inline, unsafe-eval, frame-ancestors, form-action, base-uri directives.

Cookie Security

3 checks

Secure flag, HttpOnly, SameSite attributes on every cookie.

CORS Configuration

5 checks

Origin reflection, wildcard + credentials, unsafe methods detection.

Permissions Policy

4 checks

Camera, microphone, geolocation, payment — 10 critical browser API controls.

Mixed Content

9 checks

HTTP scripts, styles, images, iframes on HTTPS pages. Auto-upgrade detection.

Subresource Integrity

4 checks

SRI hashes on CDN scripts & stylesheets. Supply chain attack protection.

JS Library Vulns

6 checks

jQuery, Bootstrap, Angular, Lodash, Moment — known CVE detection.

Info Disclosure

6 checks

Stack traces, meta generators, source maps, suspicious HTML comments.

Transport Security

4 checks

CAA records, HSTS preload readiness, DNSSEC, certificate transparency.

Redirects

3 checks

HTTP→HTTPS redirect, redirect chains, WWW normalization.

DNS & Email Auth

3 checks

SPF, DKIM, and DMARC records — prevent email spoofing from your domain.

Form & Redirect Security

5 checks

Open redirect params, CSRF tokens, insecure form actions, password fields.

Server & Info Leakage

5 checks

Exposed server versions, .env files, .git config, and other sensitive paths.

Automated monitoring

Your security posture can change overnight.

A certificate expires. A header gets removed during a deploy. A library update introduces a CVE. WebSentry monitors your sites on a daily schedule and emails you the moment your grade drops.

  • Daily automated scans — zero manual work
  • Email alerts when your grade drops
  • Historical grade tracking over time
  • Monitor up to 200 sites (Agency plans)
Set up monitoring →

Plans

Free forever for quick scans. Upgrade for history, monitoring, and API access.

Monthly Yearly Save 17%

Free

Scan any site instantly.

$0
  • Full on-screen report
  • A+ to F security grade
  • 75+ security checks
  • No history or API
Scan for free
Most popular

Pro

Developers & small teams.

$12 /mo

Billed monthly.

  • 5 monitored sites
  • Scan history & PDF export
  • REST API access
  • Email alerts
Get Started

Agency Starter

Small agency essentials.

$49 /mo

Billed monthly.

  • 25 monitored sites
  • White-label PDF reports
  • Bulk scanning
  • Priority support
Get Started

Agency Growth

Scale your client base.

$79 /mo

Billed monthly.

  • 75 monitored sites
  • Everything in Starter
  • Team seats (up to 5)
  • Custom branding
Get Started

Agency Pro

Full-scale operations.

$149 /mo

Billed monthly.

  • 200 monitored sites
  • Everything in Growth
  • $2/site overage
  • Dedicated support
Get Started

Compare all plans in detail →

Built for anyone who owns a website

From solo developers to agencies managing dozens of client sites.

Developers

Verify security headers and TLS config before shipping. Catch regressions in CI.

Startups

Stay on top of production security without a dedicated security team.

Agencies

Audit client websites, generate PDF reports, and monitor dozens of sites automatically.

Security teams

Track security posture over time and get alerted before issues become incidents.

Know your security score in 5 seconds.

Free to start. No account required. Just paste a URL.

No account needed · Sign up free to save history & set up monitoring