Find what's
exposed.

Unauthenticated external exposure scan for public files, security headers, certificate evidence, CORS, and optional takeover risk in one evidence-backed report.

Public HTTP/S targets only Reports expire after 14 days No login required
Optional scan scope
Confirm permission to enable the scan.

Not sure what you get?

How this tool works

Scanning principles

01

Unauthenticated only

Every check runs without credentials, showing what an external attacker can see.

02

Evidence-backed

Each finding includes the observed header, response signature, or request result that supports it.

03

Bounded checks

Request, concurrency, response-body, and time limits constrain each scan. Private targets and non-standard ports are blocked.

API and integrations

Run authorised scans from your agent or workflow

Create bounded public-site scans and retrieve complete evidence-backed reports through REST or JSON MCP.

Request limits apply. If you reach a limit, the response tells you when to retry. Scan only systems you are authorised to assess.

What VulnScope scans

A bounded external observation. No credentials, exploit payloads, form submissions, or destructive methods are used.

RECON

DNS and certificate history

Resolves DNS records and records certificate-transparency evidence with its limitations. Active TLS protocol and cipher testing is not included.

HDR

Security header audit

Checks for presence and correctness of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and other security headers.

PTH

Sensitive path probing

Tests for commonly exposed files: .env, .git/config, backup archives, admin panels, and configuration files.

FNG

Technology fingerprinting

Identifies server software, CMS, frameworks, and observed languages from response headers, cookies, and HTML markers.

CRS

CORS misconfiguration test

Tests whether the target returns permissive Access-Control headers that could enable cross-origin data theft.

TKO

Subdomain takeover check

Uses Certificate Transparency subdomains to probe for dangling CNAME records pointing to claimable services.

VulnScope does not exploit vulnerabilities, submit forms, bypass authentication, or test for injection. Default outbound probes use GET and OPTIONS. TRACE, WordPress deep checks, sensitive paths, and takeover checks are opt-in. No other HTTP method is sent. Use the report for defensive reconnaissance and evidence review.