Skip to content

Vigilbase Tools

Free security scanning tools to identify vulnerabilities in your websites, email configuration, and web applications.
6Active Tools
All SystemsOPERATIONAL
FREENo signup required

Website Security

Scan your websites and web applications for security issues

VERIFYCRITICAL

Website Security

Comprehensive security analysis with SSL certificate validation, security headers, HSTS, CSP, React2Shell exposure-signal review, and 21+ security checks.

WHAT IT CHECKS:
  • ›SSL certificate validation & expiration
  • ›HSTS, CSP, and security headers
  • ›Exposed sensitive files (.env, .git)
  • ›React2Shell exposure signals
MEDIUM

Headers

Quick analysis of HTTP security headers that protect against XSS, clickjacking, and other attacks.

WHAT IT CHECKS:
  • ›Content-Security-Policy (CSP)
  • ›Strict-Transport-Security (HSTS)
  • ›X-Frame-Options, X-Content-Type-Options
  • ›Permissions-Policy, Referrer-Policy
VERIFYCRITICAL

React2Shell

Check authorized React/Next.js apps for RSC response signals that require manual assessment.

WHAT IT CHECKS:
  • ›CVE-2025-55182 (React Server Components)
  • ›CVE-2025-66478 (Related Next.js advisory)
  • ›RSC response-signal inspection
  • ›Remote code execution risk

Email Security

Protect your domain from email spoofing and phishing attacks

HIGH

Email Security

Complete email authentication analysis to protect against spoofing and improve deliverability.

WHAT IT CHECKS:
  • ›SPF, DKIM, DMARC records
  • ›MX configuration
  • ›DNSSEC, MTA-STS, BIMI
  • ›Email provider detection

Infrastructure

Analyze and secure your cloud infrastructure

VERIFYHIGH

Cloudflare Checkup

Analyze your Cloudflare account and zones for security best practices. Check MFA, SSL/TLS, DNSSEC, WAF, legacy rules, and more.

WHAT IT CHECKS:
  • ›Account MFA and inventory
  • ›SSL/TLS configuration mode
  • ›DNSSEC status and validation
  • ›WAF and managed rulesets
  • ›Legacy rules and security settings
VERIFYCRITICAL

FortiBleed

Check whether a verified company domain appears in the public Hudson Rock FortiBleed domain dataset.

WHAT IT CHECKS:
  • ›Exact domain presence in the FortiBleed public list
  • ›Credential exposure count by domain
  • ›Company profile context from the source dataset
  • ›Company email verification before results are shown

Coming Soon

More security tools in development

HIGH

Port Scanner

Scan your infrastructure for open ports and identify potential attack vectors.

WHAT IT CHECKS:
  • ›Common service ports
  • ›Unnecessary open ports
  • ›Service fingerprinting
  • ›Firewall configuration
>Coming Soon
MEDIUM

DNS Security Analyzer

Analyze your DNS configuration for security issues and misconfigurations.

WHAT IT CHECKS:
  • ›DNS zone transfer
  • ›DNSSEC validation
  • ›DNS hijacking detection
  • ›Subdomain enumeration
>Coming Soon
How it works

Simple & Free

1

Enter Target

Enter your domain or URL. Some scans require email verification to prevent misuse.

2

Run Scan

Our tools analyze your target for security issues and generate a detailed report.

3

Get Results

Review findings with actionable recommendations. Optionally receive results by email.

Introducing the Vigilbase Platform

The cybersecurity operating system.

Connect the security tools you already pay for. Spin up personalised dashboards in minutes, with every log and event auditable and queryable in one place.

one.vigilbase.com/acme.examplePreview · sample data

Acme Security OS

3 sources connected

Ingesting
Cloudflare

Threats mitigated

0

Microsoft 365

Risky sign-ins

0

CrowdStrike

Open detections

0

events | where severity >= medium | last 24h
    Vigil agentWorking
    1. Investigate Impossible-travel sign-in on a finance account
    2. Fix Sessions revoked and MFA re-enrolment enforced
    3. Verify No further risky sign-ins in 30 minutes