Free passive scan

Free online pentest check

Free tool

A free, passive check of what an attacker sees from the outside: TLS, headers, exposed services and known vulnerable libraries. It doesn't attack your app. For a real pentest that tests your web app and APIs and confirms what's exploitable, start an AI pentest.

  • Security configuration analysis
  • Security headers assessment
  • TLS/SSL configuration review
  • Cookie security checks
  • CORS policy evaluation
  • Infrastructure security review
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.

How Barrion verifies this

The check runs entirely against publicly reachable surfaces, so there is nothing to install and nothing intrusive sent at your origin. Barrion resolves the target, walks the HTTP and TLS handshake, and records the raw response headers, cipher suite, certificate chain, and any redirect hops. That snapshot is then evaluated against a curated rule set drawn from OWASP ASVS, the Mozilla Observatory baseline, and current browser security defaults.

On top of the transport layer, Barrion probes adjacent signals that map to real attacker reconnaissance: DNS hygiene (CAA, SPF, DKIM, DMARC), cookie attributes on every Set-Cookie response, CORS headers and Vary: Origin, and information disclosure in server banners and error pages. Findings are de-duplicated per origin and ranked by severity.

Every issue ships with the exact evidence that produced it (the offending header, the negotiated cipher, the failing DNS lookup) and a concrete remediation pointing at the config file or platform setting most teams own. That makes the report safe to share with developers and useful as a pre-engagement input for a full pentest.

What to do with your results

After running the free pentest check, prioritize fixes by risk:

  • Critical security issues: Address immediately (missing security headers, weak TLS configuration, exposed sensitive information)
  • High-risk issues: Fix within 7-14 days (insecure cookies, CORS misconfigurations, security misconfigurations)
  • Medium-risk findings: Plan remediation within 30 days (weak TLS, missing security headers)
  • Low-risk items: Address during regular maintenance cycles

Document your fixes, run the check again to confirm them, and keep scanning on a schedule. For complex findings or a compliance requirement, you need a real pentest. Barrion's AI pentest runs continuously or on demand, paid in credits, and confirms against your live app what's exploitable.

What the free pentest check looks at

Security Configuration Analysis:
  • Security misconfigurations and weak settings
  • Missing or improperly configured security headers
  • Insecure default configurations
  • Exposed sensitive information in headers
Infrastructure Security:
  • HTTP security headers configuration (CSP, HSTS, X-Frame-Options)
  • TLS/SSL certificate health and cipher suite strength
  • Cookie security (HttpOnly, Secure, SameSite attributes)
  • CORS policy configuration and exposure
  • Server information disclosure (version leaks, headers)
  • Mixed content and HTTPS enforcement
Network & DNS Security:
  • Open ports and service exposure
  • Subdomain takeover vulnerabilities
  • DNS security (DNSSEC, CAA records)
  • Email security (SPF, DKIM, DMARC)
Security Posture Indicators:
  • TLS/SSL encryption configuration
  • Overall security configuration quality

Where this free pentest check fits

Run it before a pentest to clear the easy configuration issues, so the test spends its time on the parts that need an attacker's view. Teams use it for:

  • Before a pentest: Fix the obvious issues first
  • Between pentests: Regular checks that catch regressions
  • Small budgets: Fix what's free to fix before paying for deeper testing
  • Audit prep: Spot configuration gaps before an audit or assessment

This free check is passive, so it isn't a full penetration test. When you want one, Barrion's AI pentest is the next step. It can run continuously on a schedule or on demand from your dashboard. You pay in credits by level and the full report comes with the run. If you're weighing a yearly test against frequent ones, read how continuous pentesting works.

It tests business logic and chained requests, and findings are checked against your live app. Confirmed findings come with the request and response that show the issue. From Standard up, our security team reviews the report before release. For a larger estate, a scoped engagement with our team sets the rules and the schedule around the same pentest.

Tool-specific questions

What's the difference between this free pentest check and a penetration test?

This free check is passive. It reads publicly reachable configuration and flags common misconfigurations, and it never tries to exploit anything, so it isn't a penetration test. A penetration test actively tests for exploitable flaws, including business logic, chained requests and authorization issues that a passive scan can't reach. Barrion's AI pentest does that work. It runs continuously on the Business plan or on demand from your dashboard, paid in credits by level, with the full report included. Findings are checked against your live app, confirmed findings come with the request and response, and from Standard up a security engineer reviews the report. For a larger estate, a scoped engagement with our team sets the rules and the schedule around the same pentest.

How long does the free pentest check take?

Most checks finish in about a minute. Larger sites can take a few minutes. A manual penetration test usually takes 2 to 6 weeks, depending on scope.

Is this free check safe to run against production?

Yes. The check is passive and read-only. It only looks at publicly reachable information. It never tries to exploit a vulnerability, access private data or do anything that could harm your website or infrastructure, so it's safe to point at production.

What issues can the free pentest check find?

It finds configuration issues: security header problems, TLS/SSL misconfigurations and weak cookie flags. Paid plans also check CORS problems, open ports, subdomain takeover risks and more. It reads publicly reachable information like HTTP headers, TLS configuration and DNS records. It doesn't try to exploit anything or access private data.

Can this replace a professional penetration test?

No. This free check is passive and only reviews publicly reachable configuration. Use it for regular monitoring and catching common issues. When you need a real penetration test, Barrion's AI pentest is the next step. The credits a run spends cover the full report, and if a report doesn't hold up, email contact@barrion.io and we return the credits it spent. It tests business logic and chained requests, checks findings against your live app, and attaches the request and response to confirmed findings. From Standard up, a security engineer reviews the report before release. For a larger estate, a scoped engagement with our team sets the rules and schedule around the same pentest.

How often should I run the free pentest check?

Run it after major changes, deployments or security updates, and weekly for ongoing monitoring. Barrion's continuous monitoring schedules the scans for you, up to daily, and alerts you when a new issue shows up, so regressions between pentests don't go unnoticed.

Can I use this for compliance and audit requirements?

It helps you prepare. The report shows configuration gaps that matter for PCI DSS, HIPAA, SOC 2, ISO 27001 and GDPR, and it can serve as supporting evidence, but it doesn't count as a penetration test. Many frameworks also require periodic penetration testing, and Barrion's AI pentest produces a report you can offer for that requirement. Whether it counts is your auditor's call, and manual assessments stay optional where your program calls for them.

What should I do if critical vulnerabilities are found?

Fix them first. Apply the configuration change, run the check again to confirm it, and write down what you changed. Critical configuration issues like missing security headers, weak TLS settings or exposed sensitive information should be fixed within 24-48 hours. If you're unsure about a fix, ask a penetration tester or security consultant.

Does this work with APIs and web services?

Yes. The free check works with web applications, APIs and web services. It reads security headers, CORS policies, TLS configuration and other publicly reachable settings. To test the API itself, run Barrion's AI pentest against it. It covers business logic, chained requests and authorization, and confirmed findings come with the request and response.

How accurate are the free pentest check results?

Passive checks are accurate for configuration issues like security headers, TLS problems and misconfigurations. They can't find business logic flaws or anything else that needs active testing. For those, run Barrion's AI pentest. It checks findings against your live app and includes the request and response with every confirmed one.
Why Barrion

Built for the engineers who already have enough to fix.

Speed

Fast results

Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage

Comprehensive checks

The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action

Step-by-step fixes

Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will our auditor or enterprise customer accept the report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we store the findings and the evidence behind them, the requests and responses that confirm each issue, so you can review and reproduce them. Test credentials you add are encrypted. Data is stored and hosted in Sweden and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

Keep it covered

Fix it once, then watch it stay fixed.

A pentest shows what is exploitable today. A scheduled passive scan re-checks this tool's results and alerts you when a deploy undoes the fix.

What you get for free

18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.

What Essential adds from €199/mo

Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.