Free Security Scanner

Website security scanner for people who ship fast

Enter a URL. Get a plain-English list of vulnerabilities in seconds — security headers, exposed files, injection risks, outdated tech with known CVEs — plus AI-written steps to fix each one. No signup for the free scan, no credit card, ever.

What Vergate checks on every scan

Every scan runs a battery of automated checks against your live site. Here's the surface area it covers:

  • Security headers — Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options and more. Missing headers are the most common finding on the web, and the cheapest to fix.
  • Exposed files & directories.git/config, .env, backups, debug pages and admin panels that should never be public.
  • Open redirects — URL parameters that let attackers bounce your visitors to phishing pages.
  • Injection risk — SQL injection, XSS and command injection patterns in forms and parameters.
  • TLS & cookie security — certificate validity, and cookies missing Secure / HttpOnly / SameSite.
  • Technology stack & CVEs — we profile the frameworks and services you run and cross-reference them against known vulnerabilities, so an outdated React or exposed Next.js config shows up as a finding.
  • Tracker privacy — which analytics and tracking scripts are on your pages, and whether they create GDPR/CCPA consent exposure.

Passive scan vs active scan

Passive scanningreads your site like a browser would — no attack payloads, no risk to the target. It runs in seconds and is safe to run on any site you're allowed to test. That's what the free plan and the no-signup free scan do.

Active scanning goes further. It probes parameters and endpoints with real vulnerability tests — fuzzing, injection payloads, and thousands of ProjectDiscovery Nuclei templates — then ranks what it finds by severity and likelihood. Active scans run on paid plans through our background scanner.

Why builders keep missing vulnerabilities

The traditional security tooling was built for security teams: nmap flags, Nessus dumps, pentest PDFs. If you're a solo founder or a vibe coder shipping with AI, you don't have a security team — and you're producing code faster than any manual review can keep up with.

Vergate closes that gap with three moves: scans that run in seconds instead of hours, findings written in plain English with a severity you can act on, and AI-generated remediation steps that tell you exactly what to change and where.

Scan from your editor with MCP

Vergate's MCP server plugs into Claude Code, Cursor, Windsurf and VS Code. Your AI pair-programmer can call the scanner directly — scan a staging URL before you merge, get findings inline, and have the fix applied to the codebase in the same session.

What you get back

  • A severity-ranked list of findings (Critical → Info)
  • Evidence for each finding — the exact URL, header or payload that triggered it
  • An AI-written remediation with copy-paste fix snippets
  • A combined prompt you can hand to Claude or Copilot to fix everything at once
  • Downloadable, signed audit reports (PDF or JSON)

See what your site leaks

Run the free scan on vergate.dev — or on your own site. No account needed.

Run a free scan

Frequently asked questions

Is it really free?+

Yes. The free plan includes passive security scans with no credit card required, and the free scan needs no account at all. Paid plans add active scanning, monitoring, and more projects.

Is scanning my own site allowed? What about someone else's?+

Scan sites you own or have written authorization to test. Running scans against third-party systems without permission is against our terms and, in many places, illegal. Always get authorization first.

What does a passive scan check?+

It inspects your live site without sending attack payloads: security headers, exposed configuration and backup files, TLS certificate issues, open redirect patterns, cookies missing security flags, and the technology stack you run — including known vulnerable versions.

What does an active scan add?+

Active scans probe deeper with automated vulnerability testing — parameter fuzzing, injection checks and payload testing through ProjectDiscovery Nuclei templates — then rank every finding by severity and likelihood with a concrete fix suggestion.

How is this different from Qualys, Nessus or a pentest?+

Those tools are built for security teams and assume you know what you're doing. Vergate is built for builders: results come back in plain language, every finding includes an AI-written remediation, and you can run it from your editor via MCP. For compliance-grade audits you should still hire a professional pentester.

Scan your website right now

It takes five seconds. The scan takes seconds more. See exactly what attackers would find.

Start scanning free