{'>'} samit_hota
Free WAF Testing Tool

Is your firewall actually blocking attacks?

Fire real SQLi, XSS, RCE, LFI and 25+ other attack payloads at your Web Application Firewall and see — live — what it catches and what slips through.

28+Attack classes
340+Payloads
LiveStreamed results
Start scanning

Only test sites you own or are authorized to scan.

scanner console

Configure & run your scan

attack categories

Ready when you are

Enter a target URL on the left, choose your methods and attack categories, then hit Start Check. Results stream in here live.

awaiting target

how it works

Three steps to a firewall reality check

01

Point it at a target

Enter a URL you own or are authorized to test. Optionally auto-detect the WAF in front of it first.

02

Pick your payloads

Choose HTTP methods and attack categories — from SQLi and XSS to LFI, SSRF and command injection — or throw everything at it.

03

Watch it live

Results stream in real time — blocked, allowed or bypassed — with an exportable report in JSON, CSV or HTML.

capabilities

More than a payload cannon

Beyond firewall testing, it doubles as a lightweight recon suite for any target you're assessing.

Attack payloads

340+ payloads across 28 categories, plus advanced WAF-bypass, encoding variations and HTTP protocol manipulation.

Batch testing

Queue up to 100 URLs and test them in one run, with per-target progress and a combined export.

HTTP tests

Probe WAF bypasses via crafted headers, verb tampering and request manipulation techniques.

Full recon

CMS & technology fingerprinting, DNS, WHOIS, SSL, subdomains and email security — in one click.

Security headers

Audit CSP, HSTS, X-Frame-Options and the rest of the defensive header stack against best practice.

Speed & SEO

Page-load timing plus a meta-tag, sitemap and structured-data SEO audit with a scored summary.

faq

Common questions

What is a WAF, and what does this tool actually test?

A Web Application Firewall (WAF) sits in front of your app and filters malicious traffic. This tool sends real SQLi, XSS, RCE, LFI and other attack payloads at a target URL and reports whether each one was blocked (403/406), allowed through (200), or triggered a redirect — showing you exactly where your WAF's coverage has gaps.

Is it legal to run this against any website?

No. Only test sites you own or have explicit written authorization to test. Sending attack payloads at a target you don't control can violate computer-misuse laws (and most sites' terms of service) regardless of intent — the tool requires you to confirm authorization before every scan.

Is this free to use?

Yes, completely free, with no signup. There's a light rate limit on the public API to keep it usable for everyone; the interactive scanner in your browser isn't limited beyond that.

What should I do if a payload gets through?

A 200 response on an attack payload means your WAF didn't block that specific pattern — not necessarily that the app is vulnerable, since the payload still has to reach exploitable code. Treat it as a signal to tighten your WAF rules for that category and verify the underlying endpoint separately.

Do you store my scan results or target URLs?

Scan history is kept in your own browser's local storage for your convenience, not on a server. Requests to the target obviously reach that target's own logs, same as any other visit.