Check a website's security posture in minutes
KanaScan runs a quick, passive security scan of a public website — no account required — and produces a graded report you can read online or download as a PDF.
What gets checked
- HTTP security headers
- Content-Security-Policy, HSTS, X-Frame-Options, and other response headers.
- TLS / SSL configuration
- Certificate validity, protocol version, and common misconfigurations.
- Open network ports
- A quick scan of the most commonly exposed service ports.
- Web application analysis
- A passive OWASP ZAP baseline scan of the site's responses.
- WordPress checks
- When WordPress is detected: outdated core, plugins, themes, and exposed backups.
Every scan is passive and non-intrusive: KanaScan crawls and observes the site the way a browser would, without attempting to exploit anything. Scans typically finish in one to three minutes.