.env and credentials
Flags committed environment files and high-confidence provider, database, and private-key patterns.
Run a free website vulnerability scan on your web app. ScanMySaaS crawls the public site, checks for security issues, and delivers a prioritized report with severity scores and affected URLs.
Needs attention
8 pages checked
app.acme.test
5 findings · scanned just now
Content Security Policy is missing
Criticalapp.acme.test
Public source map reveals application code
High/_next/static/chunks/app.js.map
Session cookie has no SameSite policy
Medium/login
Product demo
Watch the original walkthrough, then start with your own public URL. The report now adds clearer findings, affected pages, and a SaaS readiness view for TLS, crawl files, and AI discovery.
60+
vulnerability checks
25
pages per scan
15
security categories
1
free first scan
Built with Codex, Claude, or Cursor?
The website scanner sees what reached production. The repository scanner checks a public GitHub repository for committed environment files, secret patterns, risky GitHub Actions, exposed client keys, weak Supabase signals, and unsafe build settings. Verified findings can be copied as technical fix prompts for your coding agent.
Read-only. No clone, package install, build, or code execution. Private repository connection is coming later.
Flags committed environment files and high-confidence provider, database, and private-key patterns.
Reviews token permissions, pull_request_target usage, secret output, and mutable third-party actions.
Looks for service-role exposure and migrations that create tables without visible RLS enablement.
Checks public secret prefixes, wildcard CORS, raw HTML sinks, eval, and production source maps.
More than a pass or fail
Most scanning tools produce a wall of warnings. ScanMySaaS keeps the affected URL, groups findings by priority, and gives paid users practical remediation for each issue.
Create free accountCrawl up to 25 reachable pages so the assessment covers more than the homepage.
Separate critical and high-risk issues from medium, low, and informational signals.
Keep every finding connected to the exact page where the scanner observed it.
Paid reports explain why a finding matters and provide practical configuration examples.
Return to earlier reports without losing the context behind previous findings.
Run a fresh scan after a release and track whether the security score improves over time.
SaaS security field guides
Focused guides connect scanner output to a safer release plan across the public app, GitHub workflows, and database boundaries.
A practical guide to CSP, HSTS, clickjacking protection, MIME sniffing, referrer policy, and permissions policy for SaaS teams.
Read guideCheck certificate trust and expiry, HTTPS redirects, HSTS, mixed content, cookies, and redirect chains before they become incidents.
Read guideConfigure robots.txt and XML sitemaps without leaking private routes or accidentally blocking the public pages that should rank.
Read guideWhat an llms.txt file can communicate, what it cannot guarantee, and how to publish a concise version for a SaaS product.
Read guideFind and remove public environment files, Git metadata, backups, debug pages, and JavaScript source maps from a SaaS deployment.
Read guideHow it works
Start with a URL, let the automated scanner inspect the public surface, then use the report to decide what to verify and fix first.
STEP 01
Enter a public URL you own or are authorized to test.
STEP 02
The crawler discovers pages and checks observable security signals.
STEP 03
Open the report, address priority findings, then run a fresh scan.
Security coverage
ScanMySaaS runs 60+ automated checks across the exposed web application. It tests public signals only—it does not log in, exploit targets, or replace a human security review.
SSL/TLS use, HTTPS redirects, HSTS, mixed content, and downgrade risks.
CSP, framing protection, MIME sniffing, permissions policy, referrers, and more.
Public environment files, Git metadata, backups, logs, source maps, and debug paths.
Secure, HttpOnly, and SameSite flags plus observable CSRF protection gaps.
Unsafe JavaScript patterns, detectable outdated libraries, and injection signals.
Technology leakage, public API docs, open redirects, DNS signals, and CORS.
llms.txt availability and a readable public resource map for compatible AI tools.
robots.txt, XML sitemap, canonical URL, homepage indexability, and security.txt.
Your first scan is free
No credit card. Use it on a website you own, keep the report, and decide what deserves attention.
Vulnerability scanner FAQ
Enter a public URL you own or are authorized to test. ScanMySaaS crawls up to 25 reachable pages, runs more than 60 automated website vulnerability checks, and returns a prioritized report with severity, affected URLs, and finding descriptions.
A website vulnerability scanner inspects the public surface of a web application for observable security issues and misconfigurations. ScanMySaaS checks transport security, response headers, cookies, forms, exposed files, client-side code, redirects, DNS and email-security signals, then groups the findings by severity.
The scanner looks for SSL and HTTPS problems, missing or unsafe security headers, risky cookie settings, exposed environment or backup files, CORS mistakes, open redirects, source maps, outdated client-side libraries, unsafe JavaScript patterns, and other publicly observable web application risks.
Yes. Your first scan is free, requires no credit card, and can inspect up to 25 reachable pages. The free report includes the security score, severity breakdown, affected URLs, and finding descriptions. Paid plans add detailed remediation guidance, monthly credits, rescans, saved history, and score trends.
ScanMySaaS is designed as a quick, browser-based outside-in check for SaaS founders and product teams. It requires no installation or command line, but it is not a replacement for Burp Suite, Nikto, manual penetration testing, or a professional security review.
No. Findings are ordered by severity and connected to the page where each issue was observed. Paid reports add practical remediation steps and configuration examples, while every result should still be verified before making a production change.