Unauthenticated scan for exposed files, missing security headers, weak TLS, CORS misconfigurations, and subdomain takeover risk — one evidence-backed report.
RECONHEADERSPATHSCORS
LIVE Scan in progress
Scanning target
01RECON
02HEADERS
03PATHS
04FINGERPRINT
05CORS
06REPORT
Reconnaissance
Security headers
Exposed paths
Fingerprint
CORS test
Build report
SCAN_FAILED
The scan could not be completed
02 Vulnerability report
example.com
—Overall grade
01
Findings
Vulnerabilities and misconfigurations discovered
02
Scan details
EVIDENCE-BACKED
DNS DNS & SSL detailsHDR Security headers auditFNG Technology fingerprintCKE Cookies PTH Exposed paths CRS CORS testTKO Subdomain takeover
Observation boundary
VulnScope performs unauthenticated checks only. It does not attempt exploitation, submit forms, or bypass authentication. Findings reflect what an external observer can discover without credentials.
03 Built for honest diagnostics
01
Unauthenticated only
Every check runs without credentials, showing what an external attacker can see.
02
Evidence-backed
Every finding includes the raw HTTP response or configuration that revealed it.
03
Safe by default
Private targets, non-standard ports, and exploitation attempts are blocked.