Paste any URL. ScanMySite probes your security headers, email & DNS armor, exposed files and JS libraries — then hands you the report with exact fixes. No AI. Measured, not guessed.
Drop your live security score anywhere — README, footer, docs. The badge re-scans on every load.
The automated scan catches the known patterns. A manual review goes deeper — business-logic flaws, auth flows, API exposure, AI prompt-injection. Tell me where to send the quote.
Same-origin JSON API. Deterministic, rate-limited, no AI. Base: /api
Scan a website. Returns score, grade, grouped findings with fixes, DNS armor status and stats.
curl -X POST /api/scan \
-H 'content-type: application/json' \
-d '{"url":"example.com"}'
→ 200 {"host":"example.com","score":73,
"grade":{"emoji":"🔒","label":"Guarded"},
"findings":[{"id":"no-csp","severity":"high",
"category":"Headers","label":"No Content-Security-Policy",
"detail":"…","fix":"…"}], …}
Engine status.
→ 200 {"ok":true,"engine":"deterministic","version":"1.0.0"}
Shields-style SVG badge with the live security score. Uses cache when available, otherwise runs a live scan. Never fakes a score — failures render a grey "scan unavailable" badge.
curl 'https://scanmysite.pages.dev/api/badge?url=example.com' \
-H 'accept: image/svg+xml'
→ 200 image/svg+xml (dark rounded badge: "ScanMySite" + score)
Request a manual security review.
curl -X POST /api/lead \
-H 'content-type: application/json' \
-d '{"name":"Ada","email":"ada@co.com",
"website":"co.com","message":"…"}'
→ 200 {"ok":true}
Errors: 400 invalid URL / blocked / non-HTML ·
429 rate limited · 500 scanner error.
Share links use ?scan=<url> (unfurls with the real score when cached) and battles use
?battle=<a>|<b> (runs both scans in your browser).