Everything in the standard scan, plus CORS misconfiguration, GraphQL introspection, exposed API docs, client-side secrets, source maps, and supply-chain (SRI) checks.
We only run passive, read-only checks — no exploitation attempts. Limited to 5 scans/hour and 20/day per visitor.
Flags a wildcard or reflected origin combined with credentialed requests — the combination that lets any site act as a logged-in user.
Checks common paths for a publicly queryable schema or exposed Swagger/OpenAPI documentation.
Pattern-matches same-origin scripts for AWS, Stripe, Google, and Slack keys — never stores the match itself, only where it was found.
Flags exposed .map files and third-party scripts loaded without an integrity attribute.