Free assessment

Find out what your attacker sees first

A free grade of your public surface — TLS, HTTP headers, cookies, DNS, content and infrastructure — with the standard behind every failure and the fix next to it. No tenant, no consent, no onboarding.

The one you can start with today

Every other assessment on this site needs an administrator to consent to something. This one does not. WebScan reads what any anonymous visitor can read, so there is nothing to install, nothing to approve, and no reason to involve anyone before you know whether there is a problem.

Send a URL. You get the grade back, usually the same working day.

What you get back

  • A grade, and the four counts behind it — passed, failed, not assessed and not applicable, kept apart so a low score can be read rather than argued with.
  • Every failure with the standard it breaks. Not "the scanner says so" but the RFC number, which is what turns a finding into a change request somebody approves.
  • Why it matters, then the fix, on each one — in the words you would use to justify the work to whoever has to schedule it.
  • The hosts you did not send us. Discovery looks for the subdomains and assets attached to the name you gave, which is usually where the surprise is.
  • What could not be assessed, said out loud. A check we could not run is never quietly counted as a pass.

And it stays free

This is not a sample of a paid product. WebScan's free tier runs the complete check set and shows every result — one URL at a time, for as long as you keep the tenant and with no expiry date on it. Nothing is held back from the check set. What it does not do is remember, and remembering is the whole of the paid product.

What the free tier does not do is remember. Nothing is written down when the scan finishes — so there is no history, no trend, no schedule, no alert when a passing check regresses, and no evidence to hand an auditor. That is the whole of what the licence buys, and it is also why the free tier can be free: a free scan is a short-lived function with no storage behind it.

What this is not

Not a penetration test. It grades configuration against published standards; as it stands it does not attempt exploitation and cannot see anything behind a login. It requests pages and reads DNS the way any visitor does — no fuzzing, no load, and it never writes anywhere. Active testing and authenticated scanning are on the WebScan roadmap; the free scan will stay unauthenticated and non-intrusive either way, so it is always safe to point at anything you own.

Scan my site

Send a URL. No tenant, no consent, no call first.

So we can reply. Nothing else is done with it.

Or email jeff@jeffops.com directly.