CVE-2025-55182
Detect unpatched React Server Components (React2Shell) with a non-executing probe plus version fingerprinting. Always free, full evidence.
Public website scanner
Free basic scan for every public URL. Honest A–F grade. Pro evidence stays locked so the internet still gets a real evaluation — and webmasters can buy the packet they can email.
Scan only sites you own or have permission to test. Terms · Free vs Pro
Detect unpatched React Server Components (React2Shell) with a non-executing probe plus version fingerprinting. Always free, full evidence.
CSP, HSTS, clickjacking, nosniff, Referrer-Policy, Permissions-Policy, stack banners, and certificate validity.
.env, .git/HEAD, package.json, and server.js — reported as exposed, with secrets redacted.
Cookies, CORS, leftover backups, JS libraries, SPF/DMARC, source maps, and CVE-2025-29927. Grade always includes them; evidence is locked until you unlock.
Unlock a report for €9 or subscribe to SafetyScan Pro for €19/month. You choose the recipient. We never cold-mail strangers.