Every page on Scan.now

The whole site in one list: 13 tools, 179 documented checks, 60 guides and the reference pages behind them.

Scanners

Every tool, each with its own checks reference and guides.

Checks reference

One page per check: What is tested, why it matters and the fix.

Checks index

Transport security (HTTPS / TLS) 12

HTTP security headers 13

Cookie security 4

Page content and JavaScript 10

Exposed files and information disclosure 14

WordPress plugins, themes and core 10

DNS and email authentication 8

Browser privacy and policy enforcement 16

File structure and malware indicators 20

Extension permissions and behaviour 9

URL and phishing indicators 13

Password security 3

Indexing and crawlability 10

Titles, headings and content 13

Links and site structure 7

Images and page weight 3

Technical SEO and speed 7

Structured data and social 4

International targeting 3

Guides

Four topic hubs and their spokes.

All guides

Pillar 1

Browser Security 12

Website Security 22

Website Security: What a Vulnerability Scan Looks For and How to Fix ItWhat Is a Vulnerability Scan? Types, Limits and What the Results MeanPassive vs Active Scanning: What Each Can Find and When Each Is AppropriateHTTP Security Headers Explained: Every Header, What It Blocks and How to Set ItContent Security Policy (CSP): A Practical Guide to Writing One That WorksHSTS Explained: Strict-Transport-Security, Preloading and the Downgrade Attacks It StopsSSL and TLS Explained: Certificates, Handshakes, Protocol Versions and Cipher SuitesTLS Certificate Errors Explained: Expired, Mismatched, Self-Signed and Untrusted ChainsThe OWASP Top 10 Explained in Plain LanguageCross-Site Scripting (XSS) Explained: Reflected, Stored, DOM-Based and How to Prevent ItSQL Injection Explained: How It Works, Real Consequences and How to Prevent ItOutdated JavaScript Libraries: Why Old jQuery and Angular Are a Real Risk and How to Find ThemSubresource Integrity (SRI): Protecting Your Site From a Compromised CDNCookie Security Flags: Secure, HttpOnly, SameSite and Cookie PrefixesMixed Content: Why an HTTPS Page Loading HTTP Resources Is Still InsecureSPF, DKIM and DMARC Explained: Stopping Email Spoofing of Your DomainExposed Files: .git, .env, Backups and Debug Pages That Leak Your Site's SecretsClickjacking Explained: How Invisible Frames Hijack Clicks and How to Prevent ItScanning a WordPress Site for Vulnerabilities: What Attackers Look For FirstCVE and CVSS Explained: How Vulnerabilities Are Named, Scored and PrioritisedOpen-Source Security Scanners Compared: Nuclei, ZAP, OpenVAS, testssl.sh, Retire.js and ClamAVHow to Read a Security Scan Report: Severity, False Positives and What to Fix First

Malware & File Safety 13

Privacy & Security 12

Reference and policies

Crawlers want the XML sitemap; this page is for people. Looking for something specific? Search the site.