Webforta Scan

A website security scanner that explains itself

Find exposed files, missing security headers, weak cookie settings, mixed content, injected-malware indicators, email spoofing gaps (SPF and DMARC) and version leaks on websites you own - with the evidence, the risk and the fix for every finding.

Scan report 1 critical 2 medium 13 checks HTTPS & redirectsEnforcedSecurity headers2 missingExposed files.env readableCookie flagsSecureVersion leakServer banner
What a scan looks like

Every finding comes with evidence and a fix

Each scan returns a clear list of checks with their status, the evidence Webforta saw, why it matters and exactly how to remediate - grouped by severity so you fix the important things first.

Try the free header check

Transport & certificates

HTTPS availability, HTTP-to-HTTPS redirects, HSTS policy and certificate expiry from Certificate Transparency logs.

Headers & cookies

Content-Security-Policy, clickjacking protection, MIME sniffing, referrer and permissions policies, permissive CORS, cookie flags.

Exposed files

Signature-confirmed checks for .git, .env, .htpasswd, SVN metadata, SQL dumps, config backups, phpinfo and server-status pages.

Technology exposure

Identifies WordPress, Drupal, Joomla, Shopify and more, and flags version banners that help attackers.

Mixed content

Scripts, stylesheets, frames, media and forms loaded or submitted over plain HTTP on HTTPS pages.

Scheduled scans

Weekly (Pro) or daily (Business) scans with alerts when new high-severity findings appear.

Safe by design

Built to be gentle with your site

  • About 20 read-only GET requests per scan, at most 4 at a time.
  • No exploits, payloads, password guessing or crawling.
  • Only domains you verify with DNS. Redirects off your site are not followed.
  • Identifiable user agent: WebfortaScanner/1.0.
Free quick check

Check any site's security headers

This public check makes one HTTPS request to the homepage - the same as a browser visit - and reviews the security headers in the response. It is not a security assessment and does not look for exposed files or vulnerabilities. Results are not stored.

See what your website shows attackers

Start a 14-day trial, verify a domain and run your first scan in about ten minutes. No card required.