Check a website's security posture in minutes

KanaScan runs a quick, passive security scan of a public website — no account required — and produces a graded report you can read online or download as a PDF.

What gets checked

HTTP security headers
Content-Security-Policy, HSTS, X-Frame-Options, and other response headers.
TLS / SSL configuration
Certificate validity, protocol version, and common misconfigurations.
Open network ports
A quick scan of the most commonly exposed service ports.
Web application analysis
A passive OWASP ZAP baseline scan of the site's responses.
WordPress checks
When WordPress is detected: outdated core, plugins, themes, and exposed backups.

Every scan is passive and non-intrusive: KanaScan crawls and observes the site the way a browser would, without attempting to exploit anything. Scans typically finish in one to three minutes.