Security score (0–100)
Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.
Vulnexa runs a deterministic, passive audit DNS, TLS, redirects, headers, CSP, privacy notice, exposures and CVE mapping then reports a security score and an AI-authorship likelihood index side by side.
Same input, same evidence, same output every run is fingerprinted.
Resolve the host, follow redirects, canonicalize the target.
TLS, DNS records, security headers and CSP directives.
Reputation, exposed paths and CVE lookups via the NVD.
Severity-tagged findings, remediation and PDF export.
Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.
Builder fingerprints, generic copy patterns, framework defaults, bundle traces and structural repetition weighed against signals of human craft. Higher means more AI.
Vulnexa fingerprints AI builders, hosting platforms and payment stacks — so vibe-coded apps get the same scrutiny as hand-written ones.
Passive OSINT plus light, non-intrusive probing no exploitation, no authentication bypass.
Gobuster DNS-mode brute force over a curated wordlist, plus certificate transparency logs and live checks on admin/staging hosts.
Gobuster DIR-mode sweep over a curated path wordlist to surface admin panels, docs, backups and other reachable routes.
SPF, DMARC policy strength, DKIM selectors, DNSSEC, CAA and NS records.
Issuer, expiry, HTTPS upgrade path and HSTS coverage.
Per-directive CSP parsing plus header drift between pages.
Secure, HttpOnly and SameSite flags on every cookie the site sets.
Dot-files, backups, source maps, debug routes, HTTP methods and leaked keys.
Newly published CVEs are technical security notices. We translate the most important ones into who may be affected and what to do next.
Not every alert affects you. Check whether you use the named product before taking action. Source: U.S. National Vulnerability Database.
A free website security scanner online — no sign-up, no intrusion, results in seconds.
Paste any domain into Vulnexa and run a scan. You get a website security checker report covering vulnerabilities, TLS, redirects, security headers and CSP a free online test of website security in one pass.
Yes. Vulnexa is a website security scanner online that finds security vulnerabilities passively: header and CSP gaps, exposed files, data-leak indicators, open ports and CVE mapping a free alternative to a website penetration test for a first-pass audit.
Vulnexa's AI website detector gives every site an AI-authorship score. It checks if website content is likely AI written by weighing builder fingerprints, framework defaults and copy patterns so you can detect AI-generated content and know if a site was built by AI.
Run a website background check: domain age and trust signals, reputation and blacklist status, privacy policy and terms presence, and a website trust score quick evidence of whether a business looks real online.
Every scan includes a website subdomain finder (Gobuster-style DNS enumeration plus certificate-transparency logs) and a directory sweep that acts as an exposed-files checker a Gobuster online tool without installing anything.
Yes, website SSL checker (issuer, expiry, HSTS), check website headers online (full security-header and CSP audit), and an open-port scanner view of the host, all included in the same free report.