Web app penetration testing, from your browser
Header, SSL/TLS, directory, XSS, SQLi, CSRF, and open-redirect checks —
the same engine as the pentest CLI, now with
scan history and reports you can share.
Before you scan anything
This tool sends real attack payloads (XSS, SQL injection probes, directory
brute-forcing) to the target. It only runs against URLs you've proven you
control, by adding a DNS TXT record or a .well-known
file — the same way domain ownership is verified for TLS certificates or
Search Console. Scanning a target without authorization is illegal in most
jurisdictions.