attack categories
Ready when you are
Enter a target URL on the left, choose your methods and attack categories, then hit Start Check. Results stream in here live.
Fire real SQLi, XSS, RCE, LFI and 25+ other attack payloads at your Web Application Firewall and see — live — what it catches and what slips through.
Only test sites you own or are authorized to scan.
scanner console
attack categories
Enter a target URL on the left, choose your methods and attack categories, then hit Start Check. Results stream in here live.
how it works
Enter a URL you own or are authorized to test. Optionally auto-detect the WAF in front of it first.
Choose HTTP methods and attack categories — from SQLi and XSS to LFI, SSRF and command injection — or throw everything at it.
Results stream in real time — blocked, allowed or bypassed — with an exportable report in JSON, CSV or HTML.
capabilities
Beyond firewall testing, it doubles as a lightweight recon suite for any target you're assessing.
340+ payloads across 28 categories, plus advanced WAF-bypass, encoding variations and HTTP protocol manipulation.
Queue up to 100 URLs and test them in one run, with per-target progress and a combined export.
Probe WAF bypasses via crafted headers, verb tampering and request manipulation techniques.
CMS & technology fingerprinting, DNS, WHOIS, SSL, subdomains and email security — in one click.
Audit CSP, HSTS, X-Frame-Options and the rest of the defensive header stack against best practice.
Page-load timing plus a meta-tag, sitemap and structured-data SEO audit with a scored summary.
faq
A Web Application Firewall (WAF) sits in front of your app and filters malicious traffic. This tool sends real SQLi, XSS, RCE, LFI and other attack payloads at a target URL and reports whether each one was blocked (403/406), allowed through (200), or triggered a redirect — showing you exactly where your WAF's coverage has gaps.
No. Only test sites you own or have explicit written authorization to test. Sending attack payloads at a target you don't control can violate computer-misuse laws (and most sites' terms of service) regardless of intent — the tool requires you to confirm authorization before every scan.
Yes, completely free, with no signup. There's a light rate limit on the public API to keep it usable for everyone; the interactive scanner in your browser isn't limited beyond that.
A 200 response on an attack payload means your WAF didn't block that specific pattern — not necessarily that the app is vulnerable, since the payload still has to reach exploitable code. Treat it as a signal to tighten your WAF rules for that category and verify the underlying endpoint separately.
Scan history is kept in your own browser's local storage for your convenience, not on a server. Requests to the target obviously reach that target's own logs, same as any other visit.