Vulnerability & URL Scanner
Audit any public-facing domain or application endpoint in real time. Instantly trace security configurations, input injection points, cryptographic compliance, and network parameters against sovereign framework rules.
Initiate domain vulnerability scan
Enter a website URL or hostname below to trigger an automated external audit.
Full perimeter coverage: 10 critical zones
Osprey Sentry scans across the complete spectrum of security boundaries. Here is what our engine inspects on every target run.
1. Input & Injection
Detects SQLi, NoSQLi, Reflected/Stored XSS, SSTI, command payload injections, and unsafe file uploads.
2. Session Security
Audits secure cookie flags (HttpOnly, Secure, SameSite), JWT integrity, password complexity, and MFA availability.
3. Access Controls
Traces privilege escalation paths, horizontal IDOR leaks, and unprotected internal routing endpoints.
4. CORS & Cross-Site
Validates domain access directives, CSRF form guards, frame hijacking protection, and open redirect parameters.
5. Server Operations
Audits SSRF pathways, deserialization, path traversal, active debug consoles, and directory indexing.
6. API Configuration
Validates payload sizes, mass assignment parameters, allowed HTTP verbs, and GraphQL introspection endpoints.
7. Cryptography & TLS
Checks cipher suite configurations, certificate authority validity, and frontend script repositories for credentials.
8. Security Headers
Audits Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), and referrer rules.
9. Deployment Hygiene
Detects exposed environment configs (.env), git history folders, server backup files, and vulnerable package dependencies.
10. Logging & Limits
Evaluates rate limits on authentication forms, administrative audit records, and anomaly alarms.