Free · No account · Results in 15 seconds
Decloak scans 8 attack surfaces simultaneously - JavaScript CVEs, hidden trackers, third-party data flows, DNS/TLS posture, subdomains, security headers, vibe-coded platform security, CMS detection and checking - and delivers a scored, graded report in under 15 seconds.
Security Score
Fair - attention needed
example.com
just now
Supabase database publicly readable via anon key
GET /rest/v1/users?select=* -> 200, 3 rows
Stripe API key exposed in /dist/main.js
sk_live_4xK9mR...
jQuery 1.12.4 - CVE-2019-11358
Known XSS vulnerability - 3 pages affected
GTM firing 3 tags to unknown domains
cdn-analytics-2847.io · reg. 6 weeks ago
AI Summary
Critical credential exposure detected in production JS bundle. A recently-registered domain is loading third-party scripts that may have been compromised...
See it in action
A two-minute walkthrough of the free scan, the AI agent investigation, and what changes when you need audit-ready evidence.
What Decloak finds
Eight attack surfaces, one scan - JavaScript CVEs, hidden trackers, exposed subdomains, DNS/TLS misconfigurations, publicly readable Supabase databases, and more. Most tools check one thing. Decloak correlates findings across every layer to surface risks single-purpose scanners miss.
Findings below marked Free come from the free single-page scan - Starter+ findings (subdomains, DNS/TLS) need a full agent scan.
Supabase database publicly readable via anon key
GET /rest/v1/users?select=* → 200, 3 rows
Stripe API key exposed in production bundle
sk_live_4xK9mRpQ2...
jQuery 1.12.4 - CVE-2019-11358 (XSS)
/assets/vendor.js · loaded on 3 pages
GTM firing to 3 unrecognised domains
cdn-analytics-2847.io · reg. 6 weeks ago
Content-Security-Policy header missing
No CSP policy found across 12 pages
Hidden 1×1 tracking pixel - doubleclick.net
<img width="1" height="1" style="display:none">
Source map exposed - /dist/app.js.map
Original source code reconstructable
Supabase service_role key exposed in client JS
Masked key: eyJhbGciOi...4kD9x2
Forgotten staging subdomain still live
staging.example.com · exposed admin login
TLS certificate expires in 4 days
issuer: Let's Encrypt · no auto-renewal detected
WordPress 6.2 - CVE-2023-2745 (Directory Traversal)
wp-includes/version.php · plugin/theme fingerprinting also run against Shopify, Magento, and 15+ other platforms
Free tier · Built with AI
Apps built with Lovable, Supabase, Base44, Bubble, and similar AI app builders share the same handful of recurring security failures - most famously, a Supabase database left publicly readable because Row Level Security was never turned on. Decloak fingerprints your stack and checks for the specific misconfigurations reported for it, on every scan, free tier included.
See vibe-coder featuresChecks whether your Supabase tables can be read by anyone using your own public anon API key - the single most common security failure in AI-app-builder projects.
Flags a leaked Supabase service_role key sitting in your client-side JavaScript before an attacker finds it - that key bypasses Row Level Security entirely.
Automatically detects Lovable, Supabase, Base44, Bubble, and Next.js - no configuration needed, no platform to select.
Checks for named, high-impact vulnerabilities like the Next.js middleware authorization bypass (CVE-2025-29927).
Who it's for
From a five-minute sanity check on a weekend project to monthly audit evidence across a whole client portfolio.
Shipped fast with AI and skipped the security review? Paste your URL and see exposed keys, missing headers, and vulnerable libraries before your users find them.
Scan your app freeScheduled scans, DNS/TLS checks, and forgotten-subdomain discovery - real security posture without an enterprise scanner budget.
See what you getSOC2, ISO 27001, NIS2, and DORA evidence, mapped automatically, plus Enterprise-tier Active Security Testing (DAST) with an independent score.
View compliance featuresOne dashboard across every client domain - subdomain discovery, DNS/TLS posture, and team seats so the whole account team can see it.
See team featuresFree scan
This is the free, single-page tier - no account needed. Want full-site coverage? That's the paid agent investigation below.
No account, no setup, no browser extension. Just a URL. Free tier results in under 15 seconds.
HTTP headers, HTML, live network traffic, JavaScript CVEs, tag managers, third-party supply chain, vibe-coded platform misconfigurations, CMS/platform fingerprinting, and behavioural analysis - simultaneously.
A graded A–F report with an AI-written executive summary. Shareable by link. Readable by anyone.
Full agent scan · Starter and up
The free tier scans one page. Paid plans deploy an AI security agent that reads each finding and decides what to look at next - following threads, fetching scripts, checking domains - until it has complete site coverage.
For compliance teams
Teams using AppCheck, Qualys, or Tenable for monthly SOC2 and ISO 27001 evidence pay thousands per year for reports that still need a pentester to interpret. Decloak delivers the same scheduled scan cadence, maps findings to SOC2, ISO 27001, NIS2, and DORA controls, and produces PDF evidence packages - at a fraction of the cost.
View compliance featuresAutomated weekly, monthly, or quarterly cadence keeps your SOC2, ISO 27001, NIS2, and DORA evidence current without manual effort.
Timestamped, exportable PDFs with a scan attestation block, formatted for evidence review.
Findings automatically tagged to ISO 27001 Annex A controls, SOC2 Trust Services Criteria, NIS2 Article 21 measures, and DORA ICT-risk articles.
Compare each scan against the last - show auditors exactly which findings have been resolved.
Mark findings as Open, In Progress, Resolved, or Accepted Risk. Auditors need to see action was taken.
One view across all your domains - current grade, last scan date, and open critical findings.
A per-domain log of every scan, deletion, and finding change - who did it and when, ready for change-control evidence.
Enterprise
Enterprise scans add safe, non-destructive active probes on top of the full investigation - forced browsing, CORS misconfiguration checks, reflected-input canaries, and authenticated scans behind a real login. Results roll up into an independent Active Testing Score and a standalone, boardroom-ready DAST report.
See Active Testing featuresForced browsing, CORS misconfiguration probes, HTTP method checks, and postMessage handler auditing - beyond passive observation.
A dedicated grade for what was actively probed, shown alongside your regular security score.
Capture a logged-in session via our browser extension - the only path that works for passkey/WebAuthn auth.
A standalone, boardroom-ready PDF scoped to Active Testing results - severity breakdown and a full "what we tested" checklist.
Starter and up
A full scan can surface hundreds of findings - useful for coverage, useless for a Monday morning to-do list. The Priority Remediation Plan collapses duplicates, ranks what's left by severity, and hands you a top-25 fix list in plain English, exportable as a PDF you can send straight to a client or developer without them ever opening the full report.
See Priority Remediation Plan featuresEvery finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."
Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.
Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.
Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.
Pricing
Free for individual page checks. Paid plans unlock full AI agent investigations, scheduled scans, and compliance reporting - at a fraction of enterprise scanner costs.
The Decloak Journal
Stories from around the web security world, plus release notes and changes to Decloak itself.

A chat widget lives in the bottom-right corner of every page now. For free accounts it's a curated FAQ router. For paid plans it's a scan-aware agent that can pull your actual findings, look up a real CVE, and explain a compliance control, without you leaving the report.

Four stories from the last few weeks: a Nextcloud misconfiguration that exposed 367,000 files, a Salesforce webpage misconfiguration behind a 13.5-million-record breach, an actively exploited SharePoint zero-day, and the year's secrets sprawl numbers.

CORS errors are annoying enough during development that a lot of teams silence them permanently with a wildcard. That single header change quietly opens your API to any website on the internet that wants to make requests on a logged-in user's behalf.

Every finding Decloak detects is now mapped to NIS2 and DORA controls alongside SOC 2 and ISO 27001. Same 36 finding categories, same underlying scan, two more frameworks to help you get ahead of this October's NIS2 deadline.