Black Box Audit
Non-invasive checks on only the submitted domain for headers, TLS, exposed files, misconfigs, robots/sitemap routes, admin paths, tech stack, and public API exposure.

Accepted inputs
https://example.com
Deterministic checks
SSL/TLS
Inspect certificate and HTTPS behavior.
Security headers
Check browser security headers.
Exposed files
Safely request known public files like .env, backup, git config, robots, and sitemap.
Tech fingerprinting
Identify public framework and platform signals.
Report sections
Related free tools
Live tools return real evidence. Registered tools stay disabled until the runner exists.
SSL Checker
Inspect the submitted HTTPS host certificate, issuer, expiry, and hostname/SAN evidence.
Public Route Checker
Safely request common public routes on the submitted domain and report status codes without exploit automation.
Exposed Files Checker
Safely check common public file paths such as .env, .git/config, backups, robots.txt, and sitemap.xml.
Subdomain Surface Checker
Run DNS-only checks for common subdomain names and report public resolutions without probing services.
Tech Stack Checker
Fetch a public page and fingerprint visible technology signals from headers, assets, generator tags, and scripts.