passive recon · zero intrusion

Two scores for every site:
security posture & AI authorship

Vulnexa runs a deterministic, passive audit DNS, TLS, redirects, headers, CSP, privacy notice, exposures and CVE mapping then reports a security score and an AI-authorship likelihood index side by side.

try

free · unlimited · no sign-in required

Educational security research only scan only what you are permitted to test.

pipeline

Four passes, two scores

Same input, same evidence, same output every run is fingerprinted.

01 Normalize

Resolve the host, follow redirects, canonicalize the target.

02 Inspect

TLS, DNS records, security headers and CSP directives.

03 Correlate

Reputation, exposed paths and CVE lookups via the NVD.

04 Report

Severity-tagged findings, remediation and PDF export.

deterministicpassive onlyevidence fingerprintedcvss + cve mapped
01 · Security

Security score (0–100)

Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.

0100
02 · Authorship

AI-authorship score (0–100)

Builder fingerprints, generic copy patterns, framework defaults, bundle traces and structural repetition weighed against signals of human craft. Higher means more AI.

0100
coverage

Scan apps built with the tools you already use

Vulnexa fingerprints AI builders, hosting platforms and payment stacks — so vibe-coded apps get the same scrutiny as hand-written ones.

  • LLovable
  • Replit logoReplit
  • EEmergent
  • CCursor
  • AAntigravity
  • Windsurf logoWindsurf
  • Stripe logoStripe
  • Copilot logoCopilot
  • Render logoRender
  • Cloudflare logoCloudflare
  • Netlify logoNetlify
toolbox

Recon tools included in every scan

Passive OSINT plus light, non-intrusive probing no exploitation, no authentication bypass.

Subdomain finder

Gobuster DNS-mode brute force over a curated wordlist, plus certificate transparency logs and live checks on admin/staging hosts.

Page & path discovery

Gobuster DIR-mode sweep over a curated path wordlist to surface admin panels, docs, backups and other reachable routes.

Email & DNS hygiene

SPF, DMARC policy strength, DKIM selectors, DNSSEC, CAA and NS records.

TLS & certificate audit

Issuer, expiry, HTTPS upgrade path and HSTS coverage.

Security headers & CSP

Per-directive CSP parsing plus header drift between pages.

Cookie inspector

Secure, HttpOnly and SameSite flags on every cookie the site sets.

Exposure sweep

Dot-files, backups, source maps, debug routes, HTTP methods and leaked keys.

Pro tools · coming soon
Bulk domain scanScheduled monitoringScanner API accessWhite-label PDFCompliance mapping (OWASP / CWE)Shareable score cards
daily security brief

Today’s software security news, in plain English

Newly published CVEs are technical security notices. We translate the most important ones into who may be affected and what to do next.

Not every alert affects you. Check whether you use the named product before taking action. Source: U.S. National Vulnerability Database.

faq

What you can check with Vulnexa

A free website security scanner online — no sign-up, no intrusion, results in seconds.

How do I check website security for free?

Paste any domain into Vulnexa and run a scan. You get a website security checker report covering vulnerabilities, TLS, redirects, security headers and CSP a free online test of website security in one pass.

Can I scan a website for vulnerabilities online?

Yes. Vulnexa is a website security scanner online that finds security vulnerabilities passively: header and CSP gaps, exposed files, data-leak indicators, open ports and CVE mapping a free alternative to a website penetration test for a first-pass audit.

Is this website AI generated? How can I tell?

Vulnexa's AI website detector gives every site an AI-authorship score. It checks if website content is likely AI written by weighing builder fingerprints, framework defaults and copy patterns so you can detect AI-generated content and know if a site was built by AI.

How do I check if a website or business is legit?

Run a website background check: domain age and trust signals, reputation and blacklist status, privacy policy and terms presence, and a website trust score quick evidence of whether a business looks real online.

How do I find subdomains and hidden pages of a website?

Every scan includes a website subdomain finder (Gobuster-style DNS enumeration plus certificate-transparency logs) and a directory sweep that acts as an exposed-files checker a Gobuster online tool without installing anything.

Does it check SSL, headers and open ports?

Yes, website SSL checker (issuer, expiry, HSTS), check website headers online (full security-header and CSP audit), and an open-port scanner view of the host, all included in the same free report.