secscan.info · reference hub

You shipped it in a weekend.
Who else can read it?

SecScan runs 127 security checks against a live web application and grades what it finds A–F. This site is the other half: what each finding means, why it carries the severity it does, and the exact change that clears it. Free to read, no account.

127
checks, every scan
25
engine modules
0
tiers or upsells

Built for apps shipped faster than they were audited

AI builders are good at features and consistently silent about security. These are the findings that come back Critical most often.

There are no tiers

Every scan runs every check. What changes how deep it reaches is access, not price.

Detail →

Domain verification

All active probing

Credentials

The surface behind the login

A second account

Broken access control (OWASP A01)

An out-of-band collector

SSRF detection (OWASP A10)

Start here

Scanning happens on secscan.us

This domain is documentation only — it holds no accounts and runs no scans. Point SecScan at a site you own, verify the domain, and it returns a graded report in a few minutes. Free during early access.

Start a scan →