Only scan websites you own or have permission to test. By scanning you confirm you are authorised.

AI Website Security Scanner

Enter any web address for a full vulnerability report — OWASP Top 10, CVE detection, SSL and security headers. First scan of every website is free. No subscription — just AI credits.

How it works

1. Enter a web address

Type or speak any URL. Your first scan of every website is completely free — no account needed.

2. AI security analysis

Our engine checks OWASP Top 10, CVEs, SSL/TLS, security headers, DNS and more — up to 40,000+ vectors on deep scans.

3. Get the full report

A clear, prioritised vulnerability report with plain-English fixes. Download as PDF or work through it with Claude.

Simple AI credit pricing

No subscription, no per-scan checkout. Buy credits once and spend them whenever you scan — 1 credit per standard scan, 5 for a deep scan. Credits never expire.

Starter

£9.99

5 AI credits

5 standard scans or 1 deep scan

MOST POPULAR

Pro

£24.99

15 AI credits

Best value for regular scanning

Elite

£69.99

50 AI credits

Our largest credit pack — ideal for heavy scanning

FOR TEAMS

Agency

£249/mo

50 client sites / month

White-label reports, team members, GitHub code scanning & scheduled scans.

View Agency plan →
New — MCP server

Scan and fix vulnerabilities inside Claude

Connect ScanLabsAI to Claude with our MCP server. Ask Claude to scan your site, read the full report, look up CVEs, and then fix the issues in your codebase — all in one conversation.

Connect to Claude

# Add ScanLabsAI to Claude Code

claude mcp add --transport http scanlabsai \

https://scanlabsai.com/api/mcp

# Then just ask:

> Scan mysite.com and fix what you find

Threat intelligence lives in the Intel Hub

The live CVE library, security best practices, remediation guides and expert research have a new home — explore real-time vulnerability intelligence in the ScanLabs Intel Hub.

Visit the Intel Hub

Frequently Asked Questions

Everything you need to know about ScanLabsAI security scanning, pricing, and features

Our scanner detects SSL/TLS issues, missing security headers (including COOP, CORP, and COEP), OWASP Top 10 (Web, API, and LLM editions), CVE 2024–2026 threats, leaked AI/LLM provider keys, exposed agentic-tooling configs, GraphQL introspection in production, outdated frameworks, and over 40,000 vulnerability vectors using our ScanLabsAI Advanced Security Engine and AI-powered analysis.

Standard scans usually finish in a minute or two. Comprehensive deep scans run more thoroughly and typically take a few minutes, occasionally up to around 20 minutes for very large or complex sites. You don't need to wait on the page — if you're signed in, deep scans run in the background and we email you and send a browser notification the moment your report is ready.

Yes, ScanLabsAI scans are completely non-intrusive and read-only. We never attempt to exploit vulnerabilities, inject code, or modify your website in any way. Our scanner behaves like a regular visitor analysing publicly available information, so there is zero risk of downtime or damage to your site.

You can scan any publicly accessible website or web application. This includes sites built with WordPress, Shopify, React, Next.js, and any other framework. The site must be live and reachable over the internet — we cannot scan localhost or intranet sites.

No. Once a deep scan has started it runs in the background, so you can close the tab or navigate away. If you're signed in, we notify you by email and by browser push notification the moment your report is ready, and your saved report is waiting for you when you return. Credits are only charged when a scan completes successfully — a failed or abandoned scan never costs you anything.

ScanLabsAI runs on AI credits — you buy a pack of credits once and spend them per scan, with no subscription. The first scan of every website is free. After that, credit packs start at £9.99 for 5 credits (our Starter pack), with Pro (15 credits, £24.99) and Agency (50 credits, £69.99) packs also available. A standard scan costs 1 credit and a comprehensive deep scan costs 5 credits. Paid scans include a downloadable PDF report and a free 30-day rescan code.

Your first scan of any website is free and gives a quick security overview — SSL/TLS, security headers and core checks — shown instantly on screen. A paid deep scan (5 credits) unlocks the full engine: over 40,000 vulnerability checks including CVE 2024–2026 detection, OWASP Top 10 (Web, API Security, and LLM Applications), AI/LLM key leak detection, GraphQL and JWT security, and outdated-framework analysis. Paid scans also include a downloadable PDF report, a saved report you can return to, a free rescan code valid for 30 days, and eligibility for the ScanLabsAI security badge.

Free scans are ephemeral — the detailed report is generated on the fly, shown to you, and never saved. For paid scans, we save your full report so you can return to it, but it's encrypted (AES-256-GCM) and held in a private, access-controlled store tied to your account, so no one else can read it. Separately, we publish a lightweight public summary for scanned domains — an overall security grade and the high-level categories of issues found — which powers shareable, search-indexable report pages. That public summary never includes your detailed findings, remediation steps, or any information that could help an attacker exploit the site.

To earn our security badge, complete a deep scan with a score above 95% and zero critical/high vulnerabilities. The badge is valid for 90 days and can be displayed on your website to build customer trust and demonstrate your commitment to security.

Every scanned domain gets a shareable public report page at scanlabsai.com/report/your-domain.com. This page shows only an overall security grade and the high-level categories of issues found — it never exposes your detailed findings, remediation steps, or anything that could help an attacker. The full report, with all findings and fixes, stays private to your account. The public page is designed so you can share proof of your security posture and so results are discoverable in search.

Our scans cover key requirements from OWASP Top 10, PCI-DSS, GDPR technical controls, and ISO 27001 security best practices. We check for secure headers, encryption standards, cookie security, data exposure risks, and more. While we don't provide formal compliance certification, our reports help you identify and fix gaps relevant to these frameworks.

We use our ScanLabsAI Advanced Security Engine combined with custom SSL/TLS analysers, extended security header checkers (including COOP, CORP, COEP), DNS security analysis, GraphQL and JWT security testing, AI/LLM provider key leak detection, outdated-framework fingerprinting, and Gemini-powered AI analysis mapped against OWASP Top 10 for Web, API Security Top 10, and LLM Applications Top 10 (2025).

Not at all. Simply enter your website URL and click scan — we handle everything else. Results are presented with clear severity ratings, plain-English explanations, and step-by-step remediation guidance that anyone can follow. If you do need help, our PDF reports can be shared with your developer or IT team.

Our AI engine analyses scan results in context, correlating multiple findings to identify attack chains and prioritise the most critical risks. It provides intelligent remediation suggestions tailored to your specific technology stack, going beyond simple rule-matching to deliver actionable security insights.

The Intelligence Hub is our free cybersecurity resource centre featuring expert-written security articles, a real-time global threat map showing live cyber attacks, and quick-scan tools. It is designed to help businesses stay informed about the latest threats and security best practices — no account required.

Yes! ScanLabsAI offers an Agency Dashboard where you can manage multiple team members, run scans for client websites, and generate branded PDF reports. It is ideal for web development agencies, IT consultancies, and managed service providers who need to deliver security assessments to their clients.

Every paid scan generates a unique rescan code that lets you re-scan the same website for free within 30 days — no credits required. It's ideal for verifying that your fixes worked after acting on our recommendations, and the code preserves the original scan type (Standard or Deep).

Reports are provided as detailed PDF documents with executive summaries, technical findings, severity classifications, and actionable remediation guidance. You can also view results in our interactive web dashboard.

Still have questions?

Contact our security experts for personalized assistance

Get in Touch
Free resource

Get the free Website Security Checklist

Not ready to scan yet? We'll email you our free 20-point checklist — the same checks our scanner runs, explained in plain English.

No spam. Just the checklist. Unsubscribe anytime.