Free security scan

Your app looks great. Is it actually safe?

Paste your URL and Scanaris checks it live for the security mistakes that sink vibe-coded apps: missing headers, leaky cookies, exposed .env files, secrets sitting in your JS bundle. No signup to see it work.

Only scan websites you own or are authorized to test. Read-only checks — we never modify anything.

Built for people who ship fast, not for security teams

Six reasons Scanaris fits how vibe coders actually work.

Real findings, not generic advice

Every check runs live against your site: response headers, cookies, TLS, exposed files. If we flag it, it's actually there — no filler checklist items.

AI fix prompts, ready to paste

Each finding comes with a fix prompt written for Cursor, Claude or your AI editor of choice. Copy, paste, done — no need to understand CSP syntax first.

Reports in your language

Findings and fixes in English or Spanish, with more languages on the way. Most scanners only speak English — we don't think that should be a tax on understanding your own risk.

An embeddable trust badge

Show your score with a badge on your own site once you've cleaned things up. Free marketing for you, proof for your visitors.

Findings ranked by what matters

Critical, high, medium, low — sorted so you fix the dangerous stuff first instead of drowning in a wall of low-severity noise.

No agent required

We scan from the outside, the same way an attacker would. Paste a URL and get a real answer in under a minute — nothing to install.

Pricing that scales with your projects

Start free. Upgrade when you have more than one site to protect.

Annual pricing shown, billed yearly (save ~30%). Monthly billing available too.

Free

See real findings before you commit to anything

€0
  • 1 scan, run anytime
  • 2-3 real findings unlocked
  • No fixes, no critical findings shown
  • Great for a first honest look
Get started

Starter

For solo makers with one project to keep honest

€17/mo, billed annually

or €24/mo billed monthly

  • 1 project
  • ~10 scans / month
  • 1 API key
  • MCP server access
  • Full findings + remediation guide
  • PDF export
Get started
Most popular

Pro

For growing projects that need to move faster

€27/mo, billed annually

or €39/mo billed monthly

  • 3 projects
  • ~150 scans / month
  • 5 API keys
  • AI fix prompts (copy-paste ready)
  • Daily monitoring
  • Live threat detection
  • Reports in multiple languages
Get started

Max

For teams and agencies managing several clients

€41/mo, billed annually

or €59/mo billed monthly

  • 10 projects
  • Unlimited scans
  • 10 API keys
  • White-label reports
  • Dedicated support
Get started

Frequently asked questions

Is it safe to scan my site with Scanaris? +

Yes. Every check is read-only: we look at public headers, cookies, certificates and files the way any visitor's browser would. We never attempt to modify, delete or inject anything into your site.

Can I scan a website that isn't mine? +

Only scan websites you own or are explicitly authorized to test. Our terms require this, and it's the same read-only, public-information approach any browser uses — but permission is still on you.

What kind of issues does it find? +

Missing or misconfigured security headers (CSP, HSTS, X-Frame-Options…), insecure cookies, overly permissive CORS, exposed files like .env or .git/config, secrets leaked in your JavaScript bundle, and TLS/certificate problems — with more checks added regularly.

Do I need to install anything? +

No. Paste your URL in the box above and the scan runs entirely from our servers. Nothing to install, no code to add — unless you later want the embeddable badge or API access.

What's the difference between the free scan and a paid plan? +

The free scan unlocks 2-3 real findings so you can see the tool actually works. Paid plans unlock every finding, AI-generated fix prompts, ongoing monitoring, and API/MCP access for automating scans.

Will scanning slow down or affect my website? +

No. Checks are lightweight, read-only HTTP requests comparable to a normal page load. We rate-limit our own scanner so it never hammers your server.