Free security scan

Your app looks great. Is it actually safe?

Paste your URL and Scanaris checks it live for the security mistakes that sink vibe-coded apps: missing headers, leaky cookies, exposed .env files, secrets sitting in your JS bundle. Free to start.

https://

Only scan websites you own or are authorized to test. We read, we never write: nothing on your site gets changed.

app.scanaris.com · how it works

STEP 2 · 8

What's your website?

https://viaro.online
Continue

Built for apps made with

  • Lovable
  • Bolt
  • v0
  • Cursor
  • Replit
  • Next.js
  • Nuxt
  • Supabase
  • Vercel
  • Netlify
  • WordPress

Built for people who ship fast, not for security teams

Six reasons Scanaris fits how vibe coders actually work.

Real problems, not generic advice

Every check runs live against your site: response headers, cookies, TLS, exposed files. If we flag it, it's actually there. No filler checklist items.

AI fix prompts, ready to paste

Each issue comes with a fix prompt written for Cursor, Claude or your AI editor of choice. Copy, paste, done, with no need to understand CSP syntax first.

Reports in your language

The whole report and its fixes in English or Spanish, with more languages on the way. Most scanners only speak English, and we don't think understanding your own risk should cost you a translation tax.

An embeddable trust badge

Show your score with a badge on your own site once you've cleaned things up. Free marketing for you, proof for your visitors.

Ranked by what actually matters

Critical, high, medium, low. We sort it that way so you fix the dangerous stuff first instead of drowning in a wall of low-severity noise.

No agent required

We scan from the outside, the same way an attacker would. Paste a URL and get a real answer in under a minute. Nothing to install.

Your whole website health, in one scan

Eight pillars run against your live site, with no agents and no code changes.

Security

Headers, cookies, exposed files, secrets, TLS and more.

SEO

Meta tags, headings, sitemap, canonical and broken links.

AI visibility (AEO)

Are ChatGPT, Claude and Perplexity able to recommend you?

Performance

Core Web Vitals (LCP, CLS, TBT) via PageSpeed.

Domain

CAA, DNSSEC and how soon your domain expires.

Email

SPF, DKIM, DMARC, MX and MTA-STS anti-spoofing.

Accessibility

WCAG basics: language, alt text, labels and headings.

Compliance

Privacy policy link and cookie consent (GDPR).

Beyond the scan

We don't just find the issues. We watch, alert and help you fix them.

Get recommended by AI

See whether ChatGPT, Claude and Perplexity recommend your site, and track it over time.

Monitoring & alerts

Automatic re-scans with email and push alerts if your score drops or something critical appears.

Uptime & status page

Continuous uptime probing and a public status page for your site.

Pricing that scales with your projects

A scan tells you where you stand today. What changes tomorrow is what actually costs you, and that's where Scanaris keeps watching.

Free

See real problems before you commit to anything

€0

free forever

  • 1 scan, run anytime
  • 2-3 real issues unlocked
  • No fixes, no critical issues shown
  • Great for a first honest look
Get started

Starter

For anyone looking after one project who wants to recheck it every time they ship

€20/mo

Billed €239/yr

  • 1 project
  • ~10 scans / month
  • 1 API key
  • MCP server access
  • Full report + remediation guide
  • PDF export
Get started
Most popular

Pro

Daily watch for a project your business already depends on

€41/mo

Billed €489/yr

  • 5 projects
  • ~40 scans / month
  • 5 API keys
  • AI fix prompts (copy-paste ready)
  • Daily monitoring (doesn't use your quota)
  • Live threat detection
  • Reports in multiple languages
Get started

Max

For agencies and teams answering for several sites at once

€89/mo

Billed €1069/yr

  • 25 projects
  • ~80 scans / month
  • 25 API keys
  • White-label reports
  • Dedicated support
Get started

Frequently asked questions

Is it safe to scan my site with Scanaris? +

Yes. Every check is read-only: we look at public headers, cookies, certificates and files the way any visitor's browser would. We never attempt to modify, delete or inject anything into your site.

Can I scan a website that isn't mine? +

Only scan websites you own or are explicitly authorized to test. Our terms require it. It's the same read-only, public-information approach any browser uses, but permission is still on you.

What kind of issues does it find? +

Missing or misconfigured security headers (CSP, HSTS, X-Frame-Options…), insecure cookies, overly permissive CORS, exposed files like .env or .git/config, secrets leaked in your JavaScript bundle, and TLS or certificate problems. We add new checks regularly.

Do I need to install anything? +

No. Paste your URL in the box above and the scan runs entirely from our servers. Nothing to install and no code to add, unless you later want the embeddable badge or API access.

What's the difference between the free scan and a paid plan? +

The free scan unlocks 2-3 real issues so you can see the tool actually works. Paid plans open the full report, AI-generated fix prompts, ongoing monitoring, and API/MCP access for automating scans.

If I fix everything it finds, why keep paying? +

Because your site doesn't stand still. Every deploy can drop a header, certificates expire after 90 days, a dependency picks up a CVE, and Google changes what it penalises. Scanaris looks again every day and tells you when something breaks, including if your site goes down or stops showing up in AI answers. The first report is only the starting point.

Will scanning slow down or affect my website? +

No. Checks are lightweight, read-only HTTP requests comparable to a normal page load. We rate-limit our own scanner so it never hammers your server.

Scan it.
Fix it.
Keep it fixed.