Free · No account · Results in 15 seconds
Paste a URL and get a scored security report in 15 seconds, free. Then go deeper: an AI agent that investigates every finding across your whole site, active penetration testing behind your login, and audit-ready evidence mapped to SOC 2, ISO 27001, NIS2, DORA, LGPD and PCI DSS.
Security Score
Fair - attention needed
example.com
just now
Supabase database publicly readable via anon key
GET /rest/v1/users?select=* -> 200, 3 rows
Stripe API key exposed in /dist/main.js
sk_live_4xK9mR...
jQuery 1.12.4 - CVE-2019-11358
Known XSS vulnerability - 3 pages affected
GTM firing 3 tags to unknown domains
cdn-analytics-2847.io · reg. 6 weeks ago
AI Summary
Critical credential exposure detected in production JS bundle. A recently-registered domain is loading third-party scripts that may have been compromised...
See it in action
A two-minute walkthrough of the free scan, the AI agent investigation, and what changes when you need audit-ready evidence.
What Decloak finds
Every layer of your site, one scan - JavaScript CVEs, hidden trackers, exposed subdomains, DNS/TLS misconfigurations, publicly readable Supabase databases, and more. Most tools check one thing. Decloak correlates findings across every layer to surface risks single-purpose scanners miss - and every report includes an explicit OWASP Top 10 coverage checklist, so what was tested is never a guess.
Findings below marked Free come from the free single-page scan - Starter+ findings (subdomains, DNS/TLS) need a full agent scan.
Supabase database publicly readable via anon key
GET /rest/v1/users?select=* → 200, 3 rows
Stripe API key exposed in production bundle
sk_live_4xK9mRpQ2...
jQuery 1.12.4 - CVE-2019-11358 (XSS)
/assets/vendor.js · loaded on 3 pages
GTM firing to 3 unrecognised domains
cdn-analytics-2847.io · reg. 6 weeks ago
Content-Security-Policy header missing
No CSP policy found across 12 pages
Hidden 1×1 tracking pixel - doubleclick.net
<img width="1" height="1" style="display:none">
Source map exposed - /dist/app.js.map
Original source code reconstructable
Supabase service_role key exposed in client JS
Masked key: eyJhbGciOi...4kD9x2
Forgotten staging subdomain still live
staging.example.com · exposed admin login
Subdomain takeover risk - dangling CNAME
old-docs.example.com → CNAME to unclaimed GitHub Pages site
TLS certificate expires in 4 days
issuer: Let's Encrypt · no auto-renewal detected
WordPress 6.2 - CVE-2023-2745 (Directory Traversal)
wp-includes/version.php · plugin/theme fingerprinting also run against Shopify, Magento, and 15+ other platforms
GraphQL introspection enabled in production
POST /graphql → full schema exposed to unauthenticated callers
Free tier · Built with AI
Apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders share the same handful of recurring security failures - most famously, a Supabase database left publicly readable because Row Level Security was never turned on. Decloak fingerprints your stack and checks for the specific misconfigurations reported for it, on every scan, free tier included.
See vibe-coder featuresChecks whether your Supabase tables can be read by anyone using your own public anon API key - the single most common security failure in AI-app-builder projects.
Flags a leaked Supabase service_role key sitting in your client-side JavaScript before an attacker finds it - that key bypasses Row Level Security entirely.
Automatically detects Lovable, Supabase, Base44, Bubble, and Next.js - no configuration needed, no platform to select.
Checks for named, high-impact vulnerabilities like the Next.js middleware authorization bypass (CVE-2025-29927).
Who it's for
From a five-minute sanity check on a weekend project to monthly audit evidence across a whole client portfolio.
Shipped fast with AI and skipped the security review? Paste your URL and see exposed keys, missing headers, and vulnerable libraries before your users find them.
Scan your app freeScheduled scans, DNS/TLS checks, and forgotten-subdomain discovery - real security posture without an enterprise scanner budget.
See what you getSOC2, ISO 27001, NIS2, DORA, LGPD, and PCI DSS evidence, mapped automatically, plus Enterprise-tier Active Security Testing (DAST) with an independent score.
View compliance featuresOne dashboard across every client domain - subdomain discovery, DNS/TLS posture, and team seats so the whole account team can see it.
See team featuresFree scan
This is the free, single-page tier - no account needed. Want full-site coverage? That's the paid agent investigation below.
No account, no setup, no browser extension. Just a URL. Free tier results in under 15 seconds.
HTTP headers, HTML, live network traffic, JavaScript CVEs, tag managers, third-party supply chain, vibe-coded platform misconfigurations, CMS/platform fingerprinting, and behavioural analysis - simultaneously.
A graded A–F report with an AI-written executive summary. Shareable by link. Readable by anyone.
Full agent scan · Starter and up
The free tier scans one page. Paid plans deploy an AI security agent that reads each finding and decides what to look at next - following threads, fetching scripts, checking domains - until it has complete site coverage.
For compliance teams
Teams using AppCheck, Qualys, or Tenable for monthly SOC2 and ISO 27001 evidence pay thousands per year for reports that still need a pentester to interpret. Decloak delivers the same scheduled scan cadence, maps findings to SOC2, ISO 27001, NIS2, DORA, LGPD, and PCI DSS controls, and produces PDF evidence packages - at a fraction of the cost.
View compliance featuresAutomated weekly, monthly, or quarterly cadence keeps your SOC2, ISO 27001, NIS2, DORA, LGPD, and PCI DSS evidence current without manual effort.
Timestamped, exportable PDFs with a scan attestation block, formatted for evidence review.
Findings automatically tagged to ISO 27001 Annex A controls, SOC2 Trust Services Criteria, NIS2 Article 21 measures, DORA ICT-risk articles, LGPD security articles, and PCI DSS v4.0 requirements.
Compare each scan against the last - show auditors exactly which findings have been resolved.
Mark findings as Open, In Progress, Resolved, or Accepted Risk. Auditors need to see action was taken.
One view across all your domains - current grade, last scan date, and open critical findings.
A per-domain log of every scan, deletion, and finding change - who did it and when, ready for change-control evidence.
Enterprise
Active Testing safely probes for plausible signal - forced browsing, CORS misconfiguration checks, reflected-input canaries - on top of the full investigation. AI Pentesting goes further: sandboxed sqlmap, dalfox, ffuf, nuclei, and jwt_tool runs attempt real exploitation against targets your scan already found. Each gets its own independent score and standalone report, never blended into the other.
Forced browsing, CORS misconfiguration probes, HTTP method checks, and postMessage handler auditing - beyond passive observation.
A dedicated grade for what was actively probed, shown alongside your regular security score.
Sandboxed sqlmap, dalfox, ffuf, nuclei, and jwt_tool runs against targets your scan already flagged - proof-of-exploit evidence, not a plausible-looking pattern match.
Computed only from confirmed pentest findings - shown alongside, never blended into, your main score or your Active Testing Score.
Starter and up
A full scan can surface hundreds of findings - useful for coverage, useless for a Monday morning to-do list. The Priority Remediation Plan collapses duplicates, ranks what's left by severity, and hands you a top-25 fix list in plain English, exportable as a PDF you can send straight to a client or developer without them ever opening the full report.
See Priority Remediation Plan featuresEvery finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."
Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.
Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.
Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.
Pricing
Free for individual page checks. Paid plans unlock full AI agent investigations, scheduled scans, and compliance reporting - at a fraction of enterprise scanner costs.
The Decloak Journal
Stories from around the web security world, plus release notes and changes to Decloak itself.

Compliance mapping now covers six frameworks. PCI DSS v4.0 added two requirements specifically to catch Magecart-style card skimming, and it turns out Decloak was already built to catch exactly that.

Every Decloak PDF was a dark-themed HTML page forced into PDF form, raw markdown leaking through, text cut off at page edges, no table of contents, no page numbers. We rebuilt it from scratch as a real, print-safe document system, because for a lot of customers, this PDF is the actual deliverable.

Most scanners test what's public. The moment a page sits behind a login, especially a passkey, they stop. Decloak's authenticated scan mode captures a real logged-in session through a browser extension instead of trying to script a login that, with WebAuthn, technically can't be scripted at all.

Three views instead of one wall of data, confidence tiers on every finding, a real fix-it plan instead of just a grade, and full visibility into what actually got checked. The free scan grew up too, same report, same rigor, real evidence from your own site.