Skip to the content

Free express scan of your site or bot

Within 24 hours we run automated checks across six areas and send you the list of weak spots. It is a surface sweep rather than an audit: we show you where to look, the analysis and the fixes are quoted separately.

Three fields, that is all

Where to send the report. We will not send anything else there.

Checks

Six areas
visible from the outside.

01

Security headers

CSP, HSTS, X-Frame-Options, cookie flags. What the server sends and what is missing.

02

Secrets on the surface

Keys and tokens in the client bundle and in exposed configs.

03

Dependencies

Known vulnerabilities in libraries and how far the versions have slipped.

04

Core Web Vitals

LCP, INP, CLS on mobile and desktop, as numbers, without root-cause analysis.

05

SEO basics

Metadata, headings, structured data, sitemap, robots, canonical links.

06

152-FZ on the surface

Policy, consent, trackers loading before the banner is answered.

Example

What the result
looks like.

A summary on the first page, then every finding with steps to reproduce and a priority. The example below is built on a made-up domain.

report-summary.txt
# express-audit · example.com
[ CRITICAL   ] 2   access to other people's orders by id
[ HIGH       ] 3   token in the client bundle
[ MEDIUM     ] 6   outdated dependencies (4 CVE)
[ LOW        ] 3   minor accessibility problems
LCP 4.1s · INP 210ms · CLS 0.04
152-FZ: counters load before consent
findings in total: 14 · time to check: 22 hours
Deliverable

What you get
within a day.

01

A list of places

What we found and where, sorted by what it puts at risk. One line per finding.

02

An honest boundary

We say plainly what automation cannot check: authorisation logic, tool permissions on bots, payment flows.

03

No exploitation detail

Reproduction, CVSS, PoC and a remediation order belong to the paid audit. We show what deserves a look, not how it breaks.

Questions

What people ask most
before applying.

Is it really free?
Yes, and that is why it is shallow. The scan costs us a couple of hours of machine time and earns us a chance to show how we work. No “just to discuss your options” calls afterwards.
How is it different from the paid audit?
Depth and method. The scan looks at what is visible from outside, automatically. The paid audit is manual OWASP work: authorisation logic, reproduction of findings, CVSS scoring, PoC and a remediation plan. Five to seven working days, from ₽120,000.
Will you break our site?
No. The scan is passive: we read server responses and run no load or destructive tests. An active pentest happens only under contract and in an agreed window.
What if there are no findings?
That happens, and we will say so. One line saying nothing critical is visible on the surface beats ten pages of padding.
Who sees the results?
Nobody. The report goes only to the contact you give us. We do not publish findings or use them as examples without written permission.

The report in a day,
the decision is yours.

Nobody calls “to clarify your decision”, and we will not add you to a mailing list unasked. If questions come up, we will write during Mon–Fri, 10:00–20:00 Moscow time.

Where to send the report. We will not send anything else there.