Free online pentest check
A free, passive check of what an attacker sees from the outside: TLS, headers, exposed services and known vulnerable libraries. It doesn't attack your app. For a real pentest that tests your web app and APIs and confirms what's exploitable, start an AI pentest.
- Security configuration analysis
- Security headers assessment
- TLS/SSL configuration review
- Cookie security checks
- CORS policy evaluation
- Infrastructure security review

How Barrion verifies this
The check runs entirely against publicly reachable surfaces, so there is nothing to install and nothing intrusive sent at your origin. Barrion resolves the target, walks the HTTP and TLS handshake, and records the raw response headers, cipher suite, certificate chain, and any redirect hops. That snapshot is then evaluated against a curated rule set drawn from OWASP ASVS, the Mozilla Observatory baseline, and current browser security defaults.
On top of the transport layer, Barrion probes adjacent signals that map to real attacker reconnaissance: DNS hygiene (CAA, SPF, DKIM, DMARC), cookie attributes on every Set-Cookie response, CORS headers and Vary: Origin, and information disclosure in server banners and error pages. Findings are de-duplicated per origin and ranked by severity.
Every issue ships with the exact evidence that produced it (the offending header, the negotiated cipher, the failing DNS lookup) and a concrete remediation pointing at the config file or platform setting most teams own. That makes the report safe to share with developers and useful as a pre-engagement input for a full pentest.
What to do with your results
After running the free pentest check, prioritize fixes by risk:
- Critical security issues: Address immediately (missing security headers, weak TLS configuration, exposed sensitive information)
- High-risk issues: Fix within 7-14 days (insecure cookies, CORS misconfigurations, security misconfigurations)
- Medium-risk findings: Plan remediation within 30 days (weak TLS, missing security headers)
- Low-risk items: Address during regular maintenance cycles
Document your fixes, run the check again to confirm them, and keep scanning on a schedule. For complex findings or a compliance requirement, you need a real pentest. Barrion's AI pentest runs continuously or on demand, paid in credits, and confirms against your live app what's exploitable.
What the free pentest check looks at
- Security misconfigurations and weak settings
- Missing or improperly configured security headers
- Insecure default configurations
- Exposed sensitive information in headers
- HTTP security headers configuration (CSP, HSTS, X-Frame-Options)
- TLS/SSL certificate health and cipher suite strength
- Cookie security (HttpOnly, Secure, SameSite attributes)
- CORS policy configuration and exposure
- Server information disclosure (version leaks, headers)
- Mixed content and HTTPS enforcement
- Open ports and service exposure
- Subdomain takeover vulnerabilities
- DNS security (DNSSEC, CAA records)
- Email security (SPF, DKIM, DMARC)
- TLS/SSL encryption configuration
- Overall security configuration quality
Where this free pentest check fits
Run it before a pentest to clear the easy configuration issues, so the test spends its time on the parts that need an attacker's view. Teams use it for:
- Before a pentest: Fix the obvious issues first
- Between pentests: Regular checks that catch regressions
- Small budgets: Fix what's free to fix before paying for deeper testing
- Audit prep: Spot configuration gaps before an audit or assessment
This free check is passive, so it isn't a full penetration test. When you want one, Barrion's AI pentest is the next step. It can run continuously on a schedule or on demand from your dashboard. You pay in credits by level and the full report comes with the run. If you're weighing a yearly test against frequent ones, read how continuous pentesting works.
It tests business logic and chained requests, and findings are checked against your live app. Confirmed findings come with the request and response that show the issue. From Standard up, our security team reviews the report before release. For a larger estate, a scoped engagement with our team sets the rules and the schedule around the same pentest.
Tool-specific questions
What's the difference between this free pentest check and a penetration test?
How long does the free pentest check take?
Is this free check safe to run against production?
What issues can the free pentest check find?
Can this replace a professional penetration test?
How often should I run the free pentest check?
Can I use this for compliance and audit requirements?
What should I do if critical vulnerabilities are found?
Does this work with APIs and web services?
How accurate are the free pentest check results?
Built for the engineers who already have enough to fix.
Fast results
Comprehensive checks
Step-by-step fixes
More free checks, for the rest of your surface.
Complete Security Scan
Security Compliance Checker
WAF Checker
Security Headers Test
TLS/SSL Security Checker
Content Security Policy (CSP) Checker
Frequently asked.
What is Barrion?
How safe is Barrion to use for security testing?
What types of security issues does Barrion identify?
What specific security checks does Barrion perform?
Will our auditor or enterprise customer accept the report?
How often does Barrion test my app?
Is Barrion suitable for security testing of all business sizes?
How does Barrion handle data security and privacy during security testing?
What if I'm not satisfied with Barrion's security testing service?
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Anything else? Email contact@barrion.io.
Fix it once, then watch it stay fixed.
A pentest shows what is exploitable today. A scheduled passive scan re-checks this tool's results and alerts you when a deploy undoes the fix.
What you get for free
18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.
What Essential adds from €199/mo
Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.