Web Vulnerability Scanner

Scan a web server for known-bad paths, vulnerable software fingerprints, and common misconfigurations — thousands of signature-based checks.

Monitor this automatically

NetTests can run this check on a schedule, preserve historical results, compare changes over time, and alert you the moment something breaks.

Start monitoring free → See all monitoring products

Frequently Asked Questions

What does this scanner check?

It probes a web server for known-bad paths, outdated/vulnerable software fingerprints, dangerous files, and common misconfigurations — thousands of signature-based checks drawn from a continuously updated database.

Why does this require authentication?

This tool fires many requests per target. From a public form it would look indistinguishable from attack traffic. Authentication and target-ownership verification ensure users only scan infrastructure they control.

How is this different from Site Exposure Scanner?

Site Exposure Scanner checks a curated set of ~120 common exposure paths (env files, backups, admin panels). This scanner additionally checks for known-CVE software fingerprints and insecure HTTP methods, drawing on a much larger, continuously updated signature database.