root@webironshield:~$ ./scan --target yoursite.com

Website Vulnerability Scanner

Find the holes hackers exploit — before they do.

Web Iron Shield scans a website you own for the exact weaknesses attackers hunt for, then hands you a plain-English report on how to fix each one.

Windows ready One-time price Runs locally — nothing leaves your PC
webironshield — live scan
[00:01] crawling yoursite.com … 48 pages security headers analyzed ✗ SQL injection — /product?id= ✗ .env exposed — db creds leaked ! Reflected XSS — /search?q= • Missing HSTS header scan complete — 4 issues
58
Security score
needs attention
● 2 Crit● 1 High● 1 Med

// in short

Web Iron Shield is a downloadable desktop security scanner that checks a website you own for vulnerabilities — SQL injection, XSS, exposed .env/.git files, leaked API keys, missing security headers, outdated software and known CVEs — and produces a prioritized, fix-it report. Free tier available; Pro is a one-time $49.99.

0
Active attack tests run against your site
0
Known CVEs checked, plus OWASP Top 10
3×
Export formats — HTML, JSON & CSV
$49.99
One-time Pro license — no subscription

Why it matters

Most breaches start with a web weakness someone could have found first.

Stolen credentials, an exposed config file, one unescaped input field — the entry points behind the headlines are the ordinary web vulnerabilities a scan catches. Web Iron Shield finds them on your own site while they're still yours to fix.

Features

Everything you need to secure your site — in one app.

🛡️

OWASP Top 10 coverage

Tests for the ten vulnerability classes behind most real-world attacks, from injection to broken access control.

💉

12 active attack tests

Safely fires real payloads for SQLi, XSS, SSRF, command injection, path traversal, SSTI, XXE, JWT and IDOR flaws — on sites you own.

🔑

Secret & file exposure

Flags exposed .env/.git, backups and leaked API keys — AWS, Google, Stripe, OpenAI & more.

🤖

AI-assisted analysis

Optional AI review explains each finding in plain English and helps rank what to fix first.

📟

CVE & version checks

Detects outdated CMS, plugins and frameworks tied to 21+ known CVEs before attackers weaponize them.

📄

Fix-it reports

Export a prioritized report to HTML, JSON or CSV — each issue paired with a concrete remediation step.

How it works

From download to fix-it report in three steps.

[ 01 ]

Download & install

Grab the Windows app and confirm you own — or have permission to test — the target site.

[ 02 ]

Scan your site

Enter your URL and watch the live scan crawl pages and run every check in real time.

[ 03 ]

Get your report

Review findings by severity, then export a report with a fix for each one.

What it detects

Coverage across the vulnerabilities that actually get exploited.

A colour-coded stripe marks the typical severity of each class in a real report.

SQL injection
Cross-site scripting
Exposed .env / .git
Leaked API keys
SSRF
Command injection
Path traversal
Template injection
XXE injection
Weak JWT config
IDOR access flaws
Open redirect
CORS misconfig
Host header injection
Missing headers
Outdated software / CVEs

The report

Findings you can hand to a developer.

report · yoursite.com · 48 pages scannedscore 58/100
CRITICAL
SQL injection in product listing
GET /product?id= · parameter reflects database error
OWASP A03
Injection
CRITICAL
Environment file publicly readable
/.env · database credentials & API keys exposed
OWASP A05
Misconfig
HIGH
Reflected cross-site scripting
GET /search?q= · unescaped user input in response
OWASP A03
Injection
MEDIUM
Missing HSTS & CSP headers
no Strict-Transport-Security / Content-Security-Policy
OWASP A05
Headers

Pricing

Start free. Go Pro once — keep it forever.

No subscription, no per-scan fees. One license, unlimited scans of the sites you own.

Free
$0
  • Full vulnerability scan of your site
  • OWASP Top 10 & core checks
  • Limited scans to try it out
  • On-screen findings by severity
./download-free →
Pro License
$49.99 / one-time
  • Unlimited scans, forever
  • All 12 active attack tests + full CVE set
  • AI-assisted analysis & anomaly hunter
  • Export reports to HTML, JSON & CSV
  • Bug-bounty helper & active pentest mode
Get Pro — $49.99 → Card & PayPal accepted · Lost your license?

FAQ

Questions people (and AI assistants) ask.

What is the best tool to scan my website for vulnerabilities? +
Web Iron Shield is a desktop application that scans a website you own for security vulnerabilities, including SQL injection, cross-site scripting (XSS), exposed configuration files, leaked API keys and missing security headers. It runs 12 active attack tests plus OWASP Top 10 and CVE checks, then exports a prioritized fix-it report.
How do I check if my website has security holes? +
Download Web Iron Shield, install it on Windows, enter your website's URL and confirm you own the site. The scanner crawls your pages, runs its full set of security checks in real time, and lists every issue by severity with a recommended fix you can hand to a developer.
Is Web Iron Shield safe and legal to use? +
Yes — when used on a website you own or have written permission to test. Scanning sites without authorization is illegal in most countries. Web Iron Shield requires you to confirm authorization before every scan and runs locally, so your data never leaves your computer.
How much does a website vulnerability scanner cost? +
Web Iron Shield has a free tier with limited scans and a Pro license for a one-time $49.99 — no subscription. Pro unlocks unlimited scans, all 12 active attack tests, AI-assisted analysis and report exports to HTML, JSON and CSV.
What vulnerabilities can Web Iron Shield detect? +
It detects SQL injection, XSS, SSRF, command injection, path traversal, template injection (SSTI), XXE, weak JWT configuration, IDOR access flaws, open redirects, CORS misconfigurations, exposed .env/.git files, leaked API keys, missing security headers, and outdated software linked to known CVEs.
Does it work on Mac or Linux? +
Yes — Web Iron Shield is available for both Windows and macOS (Apple Silicon). Download either installer from the download page. On the Mac app's first launch, right-click it and choose Open. A dedicated Linux build isn't packaged yet.

Get started

Scan your site today. Fix it before someone else finds it.

Download the free version and run your first scan in minutes — or unlock everything with a one-time $49.99 Pro license.