Free Web Scanner

See what's actually exposed.

One scan. Real findings. No account needed.

No account requiredRead-only scanNo source code required

Only scan sites you own or are authorized to test. Reports are stored and accessible via link — see how we handle scan data on the Trust page.

See what a PatchVex report looks like

example.com
✓ Scan complete
62
Needs Attention · 62/100
4 findings · 1 critical
CRITICALExposed OpenAI API key in publicly served code
MEDIUMCookie "session" missing the Secure flag
LOWMissing Content-Security-Policy header
LOWCookie "session" missing the SameSite attribute

Example scan report · illustrative findings, not a live result

What's included

Two tools. One mission.

Web Scanner

Instant security checks for any web application.

Paste a URL, get a full report in seconds.

  • TLS certificate & protocol version
  • Security headers & CSP validation
  • Exposed OpenAI, Anthropic & cloud keys
  • Cookie security flags
Try the scanner →
example.com
✓ Scan complete
62
Needs Attention · 62/100
4 findings · 1 critical
CRITICALExposed OpenAI API key in publicly served code
MEDIUMCookie "session" missing the Secure flag
LOWMissing Content-Security-Policy header
LOWCookie "session" missing the SameSite attribute
vulnpilot
5,482Total findings
47Unique hosts
19KEV matches
ScorePriorityCVE / Finding
100.0CRITICAL NOWCVE-2021-44228Log4Shell (Apache log4j2)★ KEV
100.0CRITICAL NOWCVE-2023-34362MOVEit SQL Injection★ KEV
99.8CRITICAL NOWCVE-2020-1472Zerologon (Netlogon)★ KEV
23.4MEDIUMCVE-2023-44487HTTP/2 Rapid Reset Attack
11.5LOWN/ASSH Weak Cipher Suites
VulnPilot · Open Source · MIT

Rank vulnerabilities by exploitation, not severity.

5,000 findings. 19 actually exploited right now. VulnPilot tells you which.

  • CISA KEV + FIRST EPSS + CVSS + severity composite scoring
  • SOC 2 CC7.1 & ISO 27001 evidence
  • Local-only — zero cloud upload
  • Nessus CSV import
View on GitHub →

SSRF-safe scanning

Every scan target is validated against private/internal network ranges before we ever connect. Your infrastructure is never a target.

No scan data leaves your perimeter

VulnPilot runs entirely on your machine. Findings, credentials, and scan history are never transmitted to PatchVex or any third party.

Audit-ready evidence

VulnPilot tracks every exception, SLA, and remediation with a full history. One export covers an entire audit cycle.

Open source at the core

VulnPilot is MIT-licensed and auditable. No black-box scoring — see exactly how every finding is prioritized.

Read the full Trust & Security page →

Ready to check your next deploy?

Free instant scan — no account, no credit card. Evaluating PatchVex for your team or org instead?