OpenAPI 3.0 specification for programmatic website security scanning. Import into your favorite tools.
Try the API without any authentication:
With API key authentication:
Validates SSL certificates, checks expiration, identifies protocol issues.
Checks for HSTS, CSP, X-Frame-Options, and other critical headers.
Detects common security misconfigurations and vulnerabilities.
Measures response times and identifies performance bottlenecks.
Simple pay-as-you-go pricing: