Pentest - Quick Security Check for Your Website

The pentest checks a website within seconds for typical weak spots in the configuration, such as missing security headers, insecure redirects or openly reachable login paths. For each problem you get concrete hints on how to fix it.

Careful: Only check websites you are responsible for yourself or where you have explicit permission to check. The tool is a quick first check and doesn't replace a proper penetration test by professionals.

What does the scan do?

The scan is passive and harmless. It fetches the page like a normal visitor, tests whether the HTTP variant redirects, and only asks whether five typical paths (/login, /wp-login.php, /admin, /administrator, /user/login) exist. There are no attacks, and nothing is changed. Internal addresses are blocked, only publicly reachable targets are scanned.

Start a scan

  1. Sign in. The pentest is only usable with an account.
  2. Open Pentest in the navigation (group Tools)
  3. Enter the Target URL, e.g. https://your-website.com. Without a scheme, https:// is added.
  4. Click Start scan

While the scan runs it says "Scan running ...", and afterwards the report is prepared.

The report

Right at the top are the key facts about the target:

Item Meaning
Target The address you entered
Final URL Where the request ended up after redirects
HTTP status The server's response
Response time How fast the server answered
Technologies Detected CMS, frameworks and servers
Score Overall value from 0 to 100

The score

The score starts at 100. Each critical problem costs 22 points, each warning 8. A high score doesn't mean the site is secure, only that the quick check found nothing conspicuous.

The findings

The findings are sorted into four groups:

Group Meaning
Critical issues Fix immediately
Room for improvement Improve soon
Notes Information without rating
Passed This point is fine

Each finding names:

  • Found: what the scan observed
  • Why this matters: the risk behind it
  • Where to change it: for example web server, CMS or reverse proxy
  • How to fix it: the way to the solution, often with a code example you can copy (Copy code), for Apache or PHP, say

What is checked?

Headers & TLS

  • HTTPS: is the site delivered encrypted, and does http:// redirect permanently to https://?
  • TLS certificate: can it be fully validated?
  • Security headers: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • Cookie flags: do cookies that are set have Secure, HttpOnly and SameSite?

Surface Scan

  • Forms and password fields: this is where attackers could try logins and input
  • Form actions: does a form send to an unencrypted HTTP endpoint?
  • Typical entry points: are login or admin paths publicly reachable?
  • Mixed content: does an HTTPS page load resources over HTTP?
  • Directory listing: does the server show directory contents?

Tech Fingerprint

  • Server header and X-Powered-By: do they reveal software and version?
  • Detected technologies: CMS, framework and server signatures

Common measures

  1. Enforce HTTPS: set up a permanent 301 redirect from HTTP to HTTPS
  2. Set HSTS: with it browsers only connect encrypted from then on
  3. Add security headers: above all X-Content-Type-Options, X-Frame-Options and a CSP
  4. Secure cookies with Secure, HttpOnly and SameSite
  5. Protect login areas: rate limits, brute-force protection, two-factor sign-in and, if you can, access only from certain IPs
  6. Hide version details: remove the Server and X-Powered-By headers or tone them down
  7. Disable directory listing
Recommendation: Scan your site again after every change to server, CDN or CMS, and take care of the critical findings first.

Frequently asked questions

The scan reports "The target could not be reached"

Either the address isn't publicly reachable, you misspelled it, or the server blocks the request. Internal addresses (e.g. localhost) are never scanned.

My site has 100 points, is it secure?

No. The score only rates the points that are checked. It says nothing about weaknesses in the application itself, such as SQL injection or outdated plugins.

Why are some points "Note" instead of warning?

When something cant be checked reliably, e.g. the redirect behavior, it is shown as information instead of an error.

May I scan other people's websites?

No. Only scan your own websites or ones you've been commissioned in writing to check.

Is this content helpful?

·