Unauthenticated external exposure scan for public files, security headers, certificate evidence, CORS, and optional takeover risk in one evidence-backed report.
Not sure what you get?
RECENT SCANSStored in this browser only
RECONHEADERSPATHSCORS
Scanning target
01RECON
02HEADERS
03FINGERPRINT
04PATHS
05CORS
06REPORT
Reconnaissance
Security headers
Technology fingerprint
Exposed paths
CORS test
Build report
SCAN_FAILED
The scan could not be completed
example.com
SAMPLE DATAScan information
PendingHTTP surface grade
01
Findings
Vulnerabilities and misconfigurations discovered
Export report
Anyone with this link can view the report until it expires. Share it only with approved reviewers.
02
Scan details
EVIDENCE-BACKED
DNS DNS and certificate historyCOV Scan coverageHDR Security headers auditFNG Technology fingerprintCKE Cookies PTH Exposed paths CRS CORS testTKO Subdomain takeover
Observation boundary
This grade reflects the measured main GET, security header audit, and observed unauthenticated web findings. Origin TLS protocol/cipher and certificate-transparency history are shown separately in coverage. VulnScope performs unauthenticated checks only. It does not attempt exploitation, submit forms, or bypass authentication. Findings reflect what an external observer can discover without credentials.
How this tool works
Scanning principles
01
Unauthenticated only
Every check runs without credentials, showing what an external attacker can see.
02
Evidence-backed
Each finding includes the observed header, response signature, or request result that supports it.
03
Bounded checks
Request, concurrency, response-body, and time limits constrain each scan. Private targets and non-standard ports are blocked.
API and integrations
Run authorised scans from your agent or workflow
Create bounded public-site scans and retrieve complete evidence-backed reports through REST or JSON MCP.
Request limits apply. If you reach a limit, the response tells you when to retry. Scan only systems you are authorised to assess.