OWASP Top 10 Web Application Security Engine

OWASP Website Security Checks

Automated security auditing against the OWASP Top 10. Audit insecure cookies (missing Secure, HttpOnly, SameSite), server information disclosure, unsafe CORS policies, open directory listings, publicly accessible .git and backup files, dangerous HTTP methods, and vulnerable client-side JavaScript libraries.

Popular domains: · · ·

Audit against the OWASP Top 10

Enter a URL above to check cookies, exposed files, CORS policy, headers and client-side libraries.

Instant results No account needed Free to use