Your app looks great. Is it actually safe?
Paste your URL and Scanaris checks it live for the security mistakes that sink vibe-coded apps: missing headers, leaky cookies, exposed .env files, secrets sitting in your JS bundle. Free to start.
Only scan websites you own or are authorized to test. We read, we never write: nothing on your site gets changed.
STEP 2 · 8
What's your website?
Built for apps made with
- Lovable
- Bolt
- v0
- Cursor
- Replit
- Next.js
- Nuxt
- Supabase
- Vercel
- Netlify
- WordPress
Built for people who ship fast, not for security teams
Six reasons Scanaris fits how vibe coders actually work.
Real problems, not generic advice
Every check runs live against your site: response headers, cookies, TLS, exposed files. If we flag it, it's actually there. No filler checklist items.
AI fix prompts, ready to paste
Each issue comes with a fix prompt written for Cursor, Claude or your AI editor of choice. Copy, paste, done, with no need to understand CSP syntax first.
Reports in your language
The whole report and its fixes in English or Spanish, with more languages on the way. Most scanners only speak English, and we don't think understanding your own risk should cost you a translation tax.
An embeddable trust badge
Show your score with a badge on your own site once you've cleaned things up. Free marketing for you, proof for your visitors.
Ranked by what actually matters
Critical, high, medium, low. We sort it that way so you fix the dangerous stuff first instead of drowning in a wall of low-severity noise.
No agent required
We scan from the outside, the same way an attacker would. Paste a URL and get a real answer in under a minute. Nothing to install.
Your whole website health, in one scan
Eight pillars run against your live site, with no agents and no code changes.
Security
Headers, cookies, exposed files, secrets, TLS and more.
SEO
Meta tags, headings, sitemap, canonical and broken links.
AI visibility (AEO)
Are ChatGPT, Claude and Perplexity able to recommend you?
Performance
Core Web Vitals (LCP, CLS, TBT) via PageSpeed.
Domain
CAA, DNSSEC and how soon your domain expires.
SPF, DKIM, DMARC, MX and MTA-STS anti-spoofing.
Accessibility
WCAG basics: language, alt text, labels and headings.
Compliance
Privacy policy link and cookie consent (GDPR).
Beyond the scan
We don't just find the issues. We watch, alert and help you fix them.
Get recommended by AI
See whether ChatGPT, Claude and Perplexity recommend your site, and track it over time.
Monitoring & alerts
Automatic re-scans with email and push alerts if your score drops or something critical appears.
Uptime & status page
Continuous uptime probing and a public status page for your site.
Pricing that scales with your projects
A scan tells you where you stand today. What changes tomorrow is what actually costs you, and that's where Scanaris keeps watching.
Free
See real problems before you commit to anything
free forever
- ✓1 scan, run anytime
- ✓2-3 real issues unlocked
- ✓No fixes, no critical issues shown
- ✓Great for a first honest look
Starter
For anyone looking after one project who wants to recheck it every time they ship
Billed €239/yr
- ✓1 project
- ✓~10 scans / month
- ✓1 API key
- ✓MCP server access
- ✓Full report + remediation guide
- ✓PDF export
Pro
Daily watch for a project your business already depends on
Billed €489/yr
- ✓5 projects
- ✓~40 scans / month
- ✓5 API keys
- ✓AI fix prompts (copy-paste ready)
- ✓Daily monitoring (doesn't use your quota)
- ✓Live threat detection
- ✓Reports in multiple languages
Max
For agencies and teams answering for several sites at once
Billed €1069/yr
- ✓25 projects
- ✓~80 scans / month
- ✓25 API keys
- ✓White-label reports
- ✓Dedicated support
Frequently asked questions
Is it safe to scan my site with Scanaris? +
Yes. Every check is read-only: we look at public headers, cookies, certificates and files the way any visitor's browser would. We never attempt to modify, delete or inject anything into your site.
Can I scan a website that isn't mine? +
Only scan websites you own or are explicitly authorized to test. Our terms require it. It's the same read-only, public-information approach any browser uses, but permission is still on you.
What kind of issues does it find? +
Missing or misconfigured security headers (CSP, HSTS, X-Frame-Options…), insecure cookies, overly permissive CORS, exposed files like .env or .git/config, secrets leaked in your JavaScript bundle, and TLS or certificate problems. We add new checks regularly.
Do I need to install anything? +
No. Paste your URL in the box above and the scan runs entirely from our servers. Nothing to install and no code to add, unless you later want the embeddable badge or API access.
What's the difference between the free scan and a paid plan? +
The free scan unlocks 2-3 real issues so you can see the tool actually works. Paid plans open the full report, AI-generated fix prompts, ongoing monitoring, and API/MCP access for automating scans.
If I fix everything it finds, why keep paying? +
Because your site doesn't stand still. Every deploy can drop a header, certificates expire after 90 days, a dependency picks up a CVE, and Google changes what it penalises. Scanaris looks again every day and tells you when something breaks, including if your site goes down or stops showing up in AI answers. The first report is only the starting point.
Will scanning slow down or affect my website? +
No. Checks are lightweight, read-only HTTP requests comparable to a normal page load. We rate-limit our own scanner so it never hammers your server.