websec-inspector · ~/scanner
PASSIVE MODE
WebSec Inspector
Scan a website for basic HTTPS, TLS, headers, cookies, redirects and security configuration issues — then get a visual report and hardening recommendations.
stack PHP + Tailwind + JS
mode passive
$
websec-inspector
scan
--target <url>
▌
Accepted: http://, https://, www.example.com, or example.com
Only scan systems you own or are authorized to assess.
posture overview
Security controls
Pass / fail—
Severity mixfindings only
scan metadata
rule engine
Security findings
Passive observations based on the current rule set.
http response
Response headers
state management
Cookies
navigation path
Redirect chain
Observed HTTP navigation path, including protocol changes.
hardening
Recommendations
Actionable improvements generated from the failed checks.