
WebSec Audit
Audit websites against OWASP Top 10, CWE & ISO 27001
Screenshots

WebSec Audit is a free, open-source website security scanner that audits any URL against the OWASP Top 10, CWE, WSTG, ISO 27001, and NIST standards in seconds. Just enter a URL and get an instant, citation-backed vulnerability report — every finding is grounded in real security references, so you always know which standard your site violates and exactly how to fix it.
The scanner checks security headers (HSTS, CSP, X-Frame-Options, Referrer-Policy), cookie flags (Secure, HttpOnly, SameSite), and probes for SQL injection, XSS, SSRF, path traversal, open redirects, TLS/certificate issues, missing rate limiting, and more. It crawls your entire site to map the attack surface and produces an OWASP Top 10 scorecard with actionable remediation steps.
Also includes a static code review engine, automated fix generation, and test bundle creation for developers. Free, open source, and available on the web or from the CLI.
Related products
View all
AntForms
Unlimited free submissions + free analytics + integrations +

AthleteMatrix
Your personal coach based on data from your everyday apps
More categories
All categoriesLaunched in Week 44, 2026
See the week
Uprate
AI App Store management for growing apps.

RankOrg
Rank your site on autopilot. Get customers from Google and A

Hyring
Hire more humans with AI

Shark Invoice
WhatsApp-First GST Invoicing







