Website Vulnerability / Exposure Monitor
Scan and monitor whether your website exposes sensitive interfaces and confidential files: administrative portals (/admin, /wp-admin, /wp-login.php), /xmlrpc.php, open directory indexes, client-side source maps (.js.map), debug dashboards, backup archives, public .git repos, configuration indicators (.env), and staging/test environments.
Failed to perform attack surface audit
Please check the target domain and try again.
Map your attack surface
Enter a domain above to probe for exposed admin panels, config files, source maps and staging environments.
Auditing attack surface exposure... · Probed in 0ms · Just now
Administrative & Login Interfaces
Probes for /admin, /login, /wp-admin, /wp-login.php, and database admin panels (phpMyAdmin).
WordPress XML-RPC & User Enumeration APIs
Tests /xmlrpc.php (brute force and DDoS amplification risk) and /wp-json/wp/v2/users (user enumeration).
Debug Dashboards & Diagnostic Endpoints
Checks for /phpinfo.php, /server-status, /telescope, and /actuator/env.
Client-Side JavaScript & CSS Source Maps (.map)
Verifies whether development source maps are published to production, allowing source code reconstruction.
Public .git, Environment Secrets & Backup Archives
Probes /.git/HEAD, /.env, docker-compose.yml, database dumps (.sql), and archive backups (.zip, .tar.gz).
Test & Staging Environment Exposure
Discovers public staging/dev subdomains (staging.*, dev.*, test.*, qa.*) and development environment headers.