SCANNERS
Security Scanners
Nandix runs 8 passive, response-only scanners across API and website security. Pick one to learn exactly what it checks and how to fix what it finds, or read the methodology.
API security
Sends 52 crafted URL payloads through your endpoint's parameter and reports which ones reached internal, cloud-metadata, or file-scheme targets.
Learn more →Sends five Origin probes and evaluates whether your Access-Control headers would let a hostile site read authenticated responses.
Learn more →Website security
Reads your response headers and grades the eight security headers that harden browsers against downgrade, clickjacking, and injection.
Learn more →Requests 85 sensitive paths and confirms real exposure by matching file signatures while suppressing generic soft-404 pages.
Learn more →Parses your Set-Cookie headers and checks each cookie's flags against session-security best practice.
Learn more →Completes a TLS handshake and audits the certificate, protocol versions, cipher strength, and HSTS against 20 checks.
Learn more →Resolves your domain's DNS records and audits email authentication, nameserver posture, DNSSEC, and subdomain-takeover exposure across 21 checks.
Learn more →Fetches your page's HTML and the JS bundles it links, then regex-scans them for 19 high-confidence credential types accidentally shipped to the browser — every finding masked.
Learn more →