Web Vulnerability Scanner
Scan a web server for known-bad paths, vulnerable software fingerprints, and common misconfigurations — thousands of signature-based checks.
Monitor this automatically
NetTests can run this check on a schedule, preserve historical results, compare changes over time, and alert you the moment something breaks.
Start monitoring free → See all monitoring productsFrequently Asked Questions
What does this scanner check?
It probes a web server for known-bad paths, outdated/vulnerable software fingerprints, dangerous files, and common misconfigurations — thousands of signature-based checks drawn from a continuously updated database.
Why does this require authentication?
This tool fires many requests per target. From a public form it would look indistinguishable from attack traffic. Authentication and target-ownership verification ensure users only scan infrastructure they control.
How is this different from Site Exposure Scanner?
Site Exposure Scanner checks a curated set of ~120 common exposure paths (env files, backups, admin panels). This scanner additionally checks for known-CVE software fingerprints and insecure HTTP methods, drawing on a much larger, continuously updated signature database.