Pentest Toolkit

Web app penetration testing, from your browser

Header, SSL/TLS, directory, XSS, SQLi, CSRF, and open-redirect checks — the same engine as the pentest CLI, now with scan history and reports you can share.

Sign up free Log in

Before you scan anything

This tool sends real attack payloads (XSS, SQL injection probes, directory brute-forcing) to the target. It only runs against URLs you've proven you control, by adding a DNS TXT record or a .well-known file — the same way domain ownership is verified for TLS certificates or Search Console. Scanning a target without authorization is illegal in most jurisdictions.