Free security scanners and privacy tools

13 read-only tools. None of them need an account, none of them keep what you upload, and every result links to an explanation you can act on.

Illustration of the Scan.now scanners for websites, browsers and files

Which scanner do you need?

The 13 tools below answer different questions, and running the wrong one wastes your time. The short version: Scan a site when you control it and want to know what a stranger can see; scan your browser when you want to know what every site you visit can see about you; scan a file or a link when something arrived and you do not trust it.

You own the website

Start with the website vulnerability scanner. It covers headers, TLS, cookies, exposed files and outdated JavaScript in one pass, which makes it the fastest way to find out whether anything is actually wrong. If it is a WordPress site, the WordPress scanner adds plugin, theme and core version matching against published vulnerabilities. Once security is settled, the SEO and site health audit crawls the same site for what keeps it out of search results. The single-purpose tools — SSL/TLS, security headers, email spoofing and JavaScript libraries — are the website scan split into its parts, for when you are fixing one thing and want a fast re-check.

You want to know what your browser gives away

The browser security check runs inside the browser you are reading this in: Version currency, fingerprint uniqueness, cookie and storage behaviour, and which protections are switched on. The WebRTC leak test answers the narrower question of whether your VPN is actually hiding your address, and the extension analyzer tells you what an extension can read and change once installed.

Something arrived and you do not trust it

For an attachment, the file malware scanner analyses it in memory and never writes it to disk. For a link, the phishing URL checker opens it from our server instead of your browser and tells you where it actually ends up. If you have already typed a password somewhere you should not have, the password breach check tells you whether it is in the public breach corpora, without the password leaving your browser.

What they all have in common

Every tool is passive: Nothing is exploited, no form is submitted, no payload is sent. Every finding links to its own reference page explaining the test, the risk and the fix, and how we scan sets out exactly what happens on the wire. Free scans crawl up to 25 pages; a paid plan raises that to a full-site audit when a sample is not enough.

Websites

Point these at any public site you own or rely on.

7 tools

Browsers

These run inside the browser you are using right now.

3 tools

Files

Analysed in memory, never written to disk.

1 tools

Privacy

Check a link or a password without giving anything away.

2 tools

Not sure what a result means?

Every check has its own reference page with the test, the risk and the fix.

Browse the checks reference