SCANNERS

Security Scanners

Nandix runs 8 passive, response-only scanners across API and website security. Pick one to learn exactly what it checks and how to fix what it finds, or read the methodology.

API security

SSRF Vulnerability Scanner52 probes

Sends 52 crafted URL payloads through your endpoint's parameter and reports which ones reached internal, cloud-metadata, or file-scheme targets.

Learn more →
CORS Misconfiguration Checker5 probes

Sends five Origin probes and evaluates whether your Access-Control headers would let a hostile site read authenticated responses.

Learn more →

Website security

Security Headers Checker8 probes

Reads your response headers and grades the eight security headers that harden browsers against downgrade, clickjacking, and injection.

Learn more →
Exposed Files Scanner85 probes

Requests 85 sensitive paths and confirms real exposure by matching file signatures while suppressing generic soft-404 pages.

Learn more →
Cookie Security Scanner11 probes

Parses your Set-Cookie headers and checks each cookie's flags against session-security best practice.

Learn more →
SSL/TLS Audit20 probes

Completes a TLS handshake and audits the certificate, protocol versions, cipher strength, and HSTS against 20 checks.

Learn more →
DNS Security Scanner21 probes

Resolves your domain's DNS records and audits email authentication, nameserver posture, DNSSEC, and subdomain-takeover exposure across 21 checks.

Learn more →
Secret Key Leak Scanner19 probes

Fetches your page's HTML and the JS bundles it links, then regex-scans them for 19 high-confidence credential types accidentally shipped to the browser — every finding masked.

Learn more →
Scan your site now →