● Ethical audit · read-only · ownership-verified

Is your website leaking secrets?

Enter your domain: in 30 seconds, we tell you how many API keys, sensitive files and vulnerabilities your site exposes - for free.

🚀 Launch offer · −70 % · limited quantity
Free security scan
✓ No sign-up✓ Results in ~30s✓ Non-destructive
0%
of sites have a flaw
0
flaw types checked
See a sample report Then full report €19 €5.70 · launch offer
Sécurité informatique - cadenas sur un clavier

What we detect

The leaks that cost modern websites the most - especially the ones built fast.

Critical
Exposed secret keys
Stripe, OpenAI, Claude, Gemini, AWS, GitHub… in public JS or sourcemaps.
Critical
Accessible sensitive files
.git, .env, SQL backups, directory listings.
Critical
SQL injection & reflected XSS
Non-destructive tests of your site's parameters, plus open redirects (phishing).
High
Vulnerable JS libraries
jQuery, Angular, Bootstrap, lodash… with known CVEs.
High
Missing security headers
CSP, HSTS, clickjacking and MIME-sniffing protection.
Medium
Insecure cookies
Missing Secure, HttpOnly, SameSite.
Medium
XSS-prone spots
Mixed HTTP/HTTPS content, risky DOM patterns.

An honest audit, not a reckless scanner

Most tools bombard sites with aggressive requests. We read what your server already sends - like a browser - then probe only known weak points, on your own domain, after ownership verification.

We never test a key we find (using it would be unauthorized access). We mask and hash it. Your secrets are never stored in clear text.

That's what makes the audit legal - and trustworthy.

Code source à l'écran

How it works

STEP 1

Free scan

Enter your domain. In seconds, we tell you how many vulnerabilities your site exposes, ranked by severity.

STEP 2

Unlock (€5.70)

Pay, then prove domain ownership (DNS, file or meta tag - just like Google Search Console).

STEP 3

Full report

Every detail + the fixes, the deep analysis (exposed .git/.env…), the PDF, and a copy by email.

Test it for free

The scan is free: you immediately see how many vulnerabilities your site exposes. You only pay to unlock the details and fixes.

€19 €5.70 the full report - no subscription
🚀 Launch offer · −70 % · limited quantity

For comparison, a manual security audit costs several hundred euros.

  • Every detail + the fix for each vulnerability
  • Deep analysis (exposed .git/.env files…)
  • PDF report + email delivery · 1 audit + 3 re-scans included
  • No data resold, no secret kept in clear text

VAT not applicable (French CGI art. 293 B).

Salle serveurs

Scan my site - free

No sign-up. The free scan only reads your site's public pages, like a browser.

Frequently asked questions

Is it legal to audit a website?

Yes, on your site. That's why we require proof of domain ownership before any active audit. Auditing a site you don't own is illegal - our system prevents it.

Do you break anything?

No. The audit is non-destructive: GET requests only, no data modified or deleted. To detect injections (SQL, XSS) on your own verified domain, we send harmless test values (a simple marker) into your parameters and watch the response - never a destructive payload (no DROP, no stored content). These injection tests only run after ownership verification.

What do you do with the keys you find?

Nothing. We never test them, we mask them immediately and only store a non-reversible fingerprint. The report never contains your secrets in clear text.

Is the scan really free?

Yes. The free scan reads your site's public pages and tells you how many vulnerabilities it detects, ranked by severity. You only pay to unlock the details, the fixes, the deep analysis and the PDF report.

Is this a full pentest?

No. It's an automated audit covering the most frequent and costly vulnerabilities (secrets, configuration, dependencies). It doesn't replace a thorough manual penetration test, but it catches the essentials in a minute.