Web Security Tools
Identify exposed services with port scanning, audit TLS configuration for weak ciphers and outdated protocol versions, check HTTP security headers for missing or misconfigured policies, and probe for common web vulnerabilities — all run from our network against any public host. More aggressive scanning tools require a login to prevent abuse. For continuous security posture monitoring, pair these with SSL Monitoring and HTTP Monitoring →
Vulnerability Scanners
-
Port Scanner
Polite TCP-connect port scan of a single public host (max 128 ports) with optional banner grab.
-
Web Vulnerability Scanner login
Scan a web server for known-bad paths, vulnerable software fingerprints, and common misconfigurations.
-
Site Exposure Scanner
Probe a website for exposed config files, backup dumps, admin panels, and missing security headers — the same ~120 checks attackers run.
-
Site Standards Check
Verify a site publishes security.txt, robots.txt, sitemap.xml, app-linking files, and other well-known disclosure standards.
-
HTTP Security Headers Grader
Fetch a URL and grade its HTTP security headers — CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, and more.
-
HSTS Preload Checker
Verify whether a domain qualifies for and is listed on the HSTS preload list.
-
CSP Policy Evaluator
Parse and grade a Content-Security-Policy header, flagging unsafe directives and common bypass vectors.
-
OCSP Revocation Checker
Query the OCSP responder for a certificate and verify it has not been revoked.
-
CAA Record Checker
Look up a domain's CAA DNS records to verify which Certificate Authorities are authorised to issue certificates for it.
-
WordPress Scanner login
Detect installed WordPress core, plugin, and theme versions and check them against our own vulnerability database.
-
Drupal Vulnerability Scanner login
Detect installed Drupal core and contributed-module versions and check them against our own vulnerability database.
-
Threat Surface Probe login
Run a large, actively maintained detection-signature library against a target to find CVEs, exposed panels, misconfigurations, and default credentials.
-
Deep TLS Security Audit login
Exhaustive TLS audit — protocol support, cipher suites, certificate chain, and 20+ known vulnerability checks (Heartbleed, ROBOT, POODLE, BEAST, and more).
-
TLS Implementation Fingerprinter login
Compute a genuine JA3S fingerprint from a server's real ServerHello and test whether it enforces its own cipher order.
Monitor this automatically
NetTests can run these checks on a schedule, preserve historical results, compare changes over time, and alert you the moment something breaks.
Start monitoring free → See all monitoring products