Your attack surface is already public.You just haven't read it.

Webcuris is a continuous security assessment platform for websites, repositories and AI-assisted code.

It reads what an attacker can see — certificates, headers, dependencies, code — ranks what they would reach first, and tells you whether last month's fix actually held.

Free tier · no card required · safe on production

Not ready for an account? Scan one page free, no signup

DiscoverAssessClassifyPrioritiseVerify
webcuris.com/dashboard
Assets
12
Open findings
77
Critical
2
Fixed · 7 days
+9
Posture9 assessments
86
Posture / 100
050100Jun 2, 2026Jul 28, 2026
Fix first
  • Missing HTTP Strict-Transport-Security9 assetshigh
  • TLS 1.0 negotiated2 assetshigh
  • CSP allows unsafe-inline6 assetsmedium
  • SPF record missing1 assetmedium

The product's own dashboard components, rendered with a representative dataset — not a live account.

What every assessment reads

From nothing to a read surface in three steps.

No agents to install, no traffic to reroute. The first assessment is reading what you already publish.

01

Create an account

Free, no card. You get the same scanning engine as every paid plan — the tier changes scope, never quality.

Sign-up takes under a minute

02

Point it at a domain or repository

The standard scan starts immediately — the same requests a browser makes, so it is safe to point at production. Prove ownership with a DNS record and the deeper checks unlock.

Safe on production · nothing intrusive

03

Read, fix, verify

Every finding carries severity, confidence, and a remediation package. The next scan says whether your fix actually held.

Findings tracked across every scan

Two surfaces, read the same way.

What you expose to the internet and what you ship in your repositories are the same risk seen from two sides. Both get scanned, scored, and tracked in one history.

External checks send only the requests a browser makes. Anything beyond that stays locked until you prove you own the domain.

External surface
HTTP response headers
HSTS, frame options, content-type, referrer policy
Content-Security-Policy
Directive analysis — unsafe-inline, wildcards, missing fallbacks
TLS & certificates
Protocol versions, chain trust, expiry, legacy negotiation
DNS hygiene
SPF, DMARC, CAA, DNSSEC signal
Cookies
Secure, HttpOnly, SameSite attributes
Mixed content
Insecure subresources on a secure page
Subdomains
Certificate Transparency log enumeration
Code surface
Dependencies
8 package ecosystems resolved against OSV.dev
Secrets
Credential patterns in source, masked before storage
Dockerfile
Root user, unpinned bases, baked secrets, unsafe ADD
Kubernetes
Privileged pods, capabilities, host namespaces, limits
Code patterns
eval, shell interpolation, SQL concatenation, weak hashes
LLM usage
Prompts built from request input, agents wired to shell

What's inside the engine.

Everything below is implemented and running today. Nothing on this page is a roadmap item wearing present tense.

Individual findings don't breach you. Paths do.

The correlation engine reads findings together — within a scan and across every asset you own — and names the compound risk no single row would have shown you.

No HSTSTLS 1.0 acceptedDowngrade & intercept

A lifecycle, not a list

Every finding is fingerprinted and tracked across scans: new, persisting, fixed — and regressed, counted every time it comes back.

Confidence on every row

Confirmed, strong indication, potential, informational. A scanner that states how sure it is lets you tell a fact from a pattern.

EPSS on dependencies

Public exploit-prediction scores on dependency findings, so “critical” and “actually being exploited” stay distinguishable.

Alerts that cannot mask each other

Email and webhooks — Slack, PagerDuty, Datadog, Splunk — fire independently from one decision. A failing webhook cannot suppress the email.

Nine report types

Plus SBOM and JSON export for the tools that come after the read.

Technical reportCompliance viewDeveloper reportHardening configAttacker's viewIncident runbookExecutive reportRemediation planAI security report

Your code calls models now.
That's attack surface too.

Prompts, agents, and the dependencies models hallucinate are read by the same engine, with the same severity-and-confidence discipline as every other finding.

AI usage, read from source

Code scan

Prompts assembled from request input, agents wired to shells, and secrets inside prompt templates are flagged where they live — in your repository.

finding · LLM prompt built from unsanitised request body · potential

Red-team checks for LLM endpoints

Web scan

Injection surface, system-prompt leakage, and tool abuse are exercised under the same authorisation rules as every other check — nothing intrusive until you prove ownership.

locked until domain ownership is verified

Hallucinated dependencies

Supply chain

Package names that models like to invent are checked against what actually exists in the registry. Slopsquatting is a supply-chain vector now; this is the check for it.

finding · dependency not present in registry · strong indication

Agents under guardrails

Platform

The platform's own agent sessions run with least privilege, and destructive actions stop at a human approval checkpoint that an API key cannot satisfy.

approval required · api-key actors cannot approve their own actions

Open one finding

A row is only useful if it survives being opened.

Any scanner can produce a list. This is what one row looks like all the way down — and the four questions it has to answer before it has earned your afternoon.

HighConfirmed9 assets affected

Missing HTTP Strict-Transport-Security (HSTS) header

app.example.com · headers · CWE-319

A check fired, and it says how sure it is.

Category

Response headers · CWE-319

What the check looks for

A Strict-Transport-Security header on every HTTPS response, with a max-age long enough to survive between visits.

Severity

High — exploitable, but needs the attacker on the network path.

Confidence

Confirmed — the header is absent in the response, not inferred.

Severity is how bad this is if exploited. Confidence is how certain the scanner is that it is real — a separate axis, printed on every row, so you can tell a fact from a pattern before you spend an afternoon on it.

One representative finding, with the wording this check actually emits — not a live account.

8
Package ecosystems
11
Check categories
5
Severity levels
4
Report types

What it doesn't do, in writing.

A security vendor that lists only strengths is asking you to do the discovery yourself. The Security Policy documents the limitations in the same detail as the capabilities.

Trust Center →

No SOC 2, ISO 27001, or third-party penetration test. Compliance mappings are situational context, not audit evidence.

Safe on production by default. Checks that go beyond an ordinary browser visit stay locked until domain ownership is proven by DNS record or hosted file.

Your data stays yours. Findings are exportable, and account deletion is self-service — no request queue, no retention you didn't choose.

Findings can be wrong. False positives and negatives both happen, which is exactly why confidence sits on every row.

Priced on how much you watch.

Every plan runs the same engine and the same checks. What changes is how many assets you cover.

Free
$0forever

Assess one thing properly.

  • 1 domain and 1 repository
  • The standard scan — the same requests an ordinary visitor makes, safe against production
  • Severity, confidence and a fix for every finding
See full plan
ProRecommended
$39per month

or $399/year — nearly 2 months free

Continuous assessment for a growing surface.

  • 5 domains and 5 repositories
  • Continuous monitoring on a schedule you set
  • Cross-asset correlation — credential reuse, chronic regression
See full plan
Business
$79per month

or $799/year — nearly 2 months free

The same product, with more room.

  • 12 domains and 12 repositories
  • Everything in Pro — every feature, at the same depth
  • Room for a larger portfolio under one account
See full plan

Asked, answered.

The questions people arrive with — including the ones about what this deliberately refuses to do.

Webcuris is a continuous security assessment platform for websites, code repositories and AI-assisted code. It scans a site the way an ordinary visitor's browser would — headers, cookies, TLS, DNS and redirect behaviour — analyses repositories and their dependencies for known vulnerabilities and committed secrets, and then re-runs those checks on a schedule so a finding that comes back is reported as a regression rather than as a new discovery. It is built for developers, DevOps and security engineers at small and mid-sized software teams. The free plan covers one domain and one repository at no cost; paid plans start at $39 a month. It is not a website builder and not a design agency.

Find out what you're publishing.

Run an assessment against a domain you own and read the result in a few minutes. Free tier, no card, nothing intrusive.

Safe on production · prove ownership to scan deeper

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

We reply to this address, so a disposable one will not reach you.

+91

0 / 4000