// Agent category
HTTPS/TLS, security headers, cookies & privacy, and information-disclosure checks
Review crawl-visible technical signals related to how safely a public site is delivered. These tools inspect HTTPS and insecure resources, selected response headers, the presented TLS certificate, cookie and consent references, and information-disclosure signals such as directory listings, exposed source maps, and references to sensitive paths. They do not establish legal compliance, prove a site is secure, or replace dedicated vulnerability testing.
5 agents
Review crawl-visible HTTPS, policy, contact, identity, social-proof wording, and selected external-reference patterns
Detect public policy links, consent wording, and tracker references
Review captured URL schemes, selected response-header presence, and explicit HTTP references in available HTML
Inspect the live TLS certificate from one handshake — expiry, hostname coverage, trust chain, and negotiated protocol
Review crawled HTML and links for directory listings, sensitive-path references, exposed source maps, version disclosure, and missing Subresource Integrity
Yes. The category’s agents are available on the Free plan within its monthly scan allowance, and a guest can try an initial scan without creating an account. Usage and crawl depth depend on the scan type and plan.
No. Header presence is one layer of browser-facing configuration, and the right policy depends on the application. Use dedicated vulnerability testing, dependency scanning, secure development review, and operational monitoring to assess risks that a public crawl cannot see.
It reviews only what the crawl captured — directory listings, references to paths that should never be public (.git, .env, backups), exposed source maps, framework version disclosure, and third-party scripts loaded without Subresource Integrity. A reference is a lead to verify, not proof of a breach; it makes no active or intrusive requests.