🔐
SSL / TLS Deep Scan
Certificate validity, expiry, weak ciphers, TLS 1.3 support, self-signed detection
🛡️
Security Headers
CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy — all checked
🔌
Port Scanner
25 common ports checked — flags dangerous open ports (MySQL, RDP, MongoDB, Redis)
🛒
E-Commerce Security
PCI DSS compliance, payment gateway checks, Shopify & WooCommerce-specific analysis
🔵
WordPress Deep Scan
Plugin enumeration, XML-RPC, user enumeration, debug log exposure, version leaks
📧
Email Security (SPF/DMARC)
Checks SPF, DMARC, CAA records — prevents domain spoofing & phishing attacks
📁
Sensitive File Exposure
.env, .git, wp-config backups, phpMyAdmin, database dumps — 20 paths checked
🌐
Subdomain Enumeration
30+ common subdomains checked — finds forgotten test/dev environments
📊
PDF Security Report
Professional downloadable report with every finding + exact fix instructions