Free passive scan

Free Vulnerability Scanner

Free tool

Scans for vulnerable JS libraries (matched to CVE IDs), weak TLS, missing security headers, and insecure cookies. Severity-ranked findings with step-by-step fixes.

  • Security misconfiguration detection
  • Vulnerable library detection
  • Configuration vulnerability scanning
  • Security posture assessment
  • Risk severity scoring
  • Remediation guidance
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.

Why vulnerability scanning matters

Regular vulnerability scanning helps you identify and fix security issues before attackers exploit them. This tool provides:

  • Early detection: Find vulnerabilities before they're exploited in production
  • Risk prioritization: Focus on critical vulnerabilities first with severity scoring
  • Compliance support: Meet security scanning requirements for PCI DSS, HIPAA, SOC 2
  • Continuous monitoring: Track vulnerabilities over time and detect new issues
  • Remediation guidance: Get actionable steps to fix each vulnerability

Combine automated vulnerability scanning with manual security testing for comprehensive coverage. Use this tool for regular security assessments and continuous vulnerability monitoring.

What to do with vulnerability scan results

After scanning for vulnerabilities, prioritize remediation based on risk severity:

  • Critical security issues: Address immediately (missing security headers, weak TLS configuration, exposed sensitive information)
  • High-risk issues: Fix within 7 days (insecure cookies, vulnerable libraries, security misconfigurations)
  • Medium-risk issues: Plan remediation within 30 days (misconfigurations, weak encryption)
  • Low-risk findings: Address during regular maintenance cycles

Document all fixes, verify remediation with rescanning, and establish a regular scanning schedule. For complex vulnerabilities or compliance requirements, consider engaging security professionals for validation and deeper analysis.

What this vulnerability scanner detects

Vulnerable Libraries & Dependencies:
  • Vulnerable JavaScript libraries detection
  • Outdated library version identification
  • Known security issues in frontend dependencies
  • Library security posture assessment
Security Misconfigurations:
  • Insecure default configurations
  • Missing or weak security headers
  • Improper TLS/SSL configuration
  • Insecure cookie settings
  • Exposed sensitive information in headers
Configuration Vulnerabilities:
  • Security header misconfigurations
  • Cookie security issues
  • Insecure security configurations
  • Missing security controls
  • Weak encryption settings
Infrastructure Vulnerabilities:
  • TLS/SSL configuration weaknesses
  • DNS security misconfigurations
  • Email security vulnerabilities
  • Network exposure and open ports
  • Subdomain takeover risks

How Barrion verifies this

Barrion combines several passive signals without testing your application the way an attacker would. For libraries, the scanner crawls your pages and matches the JavaScript libraries they load against the retire.js vulnerability database, which lists known CVEs and the versions that fix them.

For configuration vulnerabilities, Barrion replays the full TLS handshake, parses every response header, and inspects cookie attributes the same way a browser would, then compares the result against the OWASP Secure Headers Project, Mozilla's TLS guidelines, and the relevant RFCs. Each finding shows the value that triggered it, so you can reproduce the check yourself with curl or openssl.

Findings are then deduplicated and ranked by severity so you see a stable, ordered list rather than a wall of raw output. Every finding ships with the source signal, the affected URL, and a concrete remediation step, which is what makes the report safe to hand directly to an engineering team or attach to a compliance ticket.

Tool-specific questions

What does a vulnerability scanner check?

A vulnerability scanner tests your web app for common security misconfigurations, outdated or vulnerable JavaScript libraries (with known CVEs), and configuration issues that create exploitable risk. Barrion's scanner is passive - no agent or code access needed. Results include severity scoring and step-by-step remediation so you know what to fix first.

What's the difference between a vulnerability scanner and a penetration test?

A vulnerability scanner uses passive analysis to identify security misconfigurations and configuration vulnerabilities. A penetration test involves manual testing by security experts with active vulnerability exploitation to find complex vulnerabilities, business logic flaws, and advanced attack scenarios. Use passive vulnerability scanning for regular monitoring and configuration review, and penetration testing for comprehensive security assessments.

How accurate are vulnerability scanner results?

Passive vulnerability scanners are highly accurate for detecting security misconfigurations, vulnerable libraries, and configuration issues. However, they cannot detect active vulnerabilities, business logic flaws, or advanced attack scenarios that require active testing. Always validate findings and supplement with manual penetration testing for comprehensive security assurance.

How often should I run vulnerability scans?

Run vulnerability scans after any major changes, deployments, or security updates. For ongoing monitoring, weekly scans are recommended. Use Barrion's continuous monitoring for scheduled scans, up to daily, and instant alerts when new vulnerabilities are detected. This ensures you catch new issues quickly and maintain security posture.

Can this scanner detect zero-day vulnerabilities?

No, our vulnerability scanner focuses on configuration vulnerabilities and security misconfigurations that can be detected through passive analysis. Zero-day vulnerabilities are unknown flaws that haven't been publicly disclosed. For zero-day protection, combine vulnerability scanning with intrusion detection, security monitoring, and professional security assessments.

What types of vulnerabilities can this scanner find?

Our vulnerability scanner detects vulnerable libraries, security misconfigurations, infrastructure weaknesses (TLS issues, DNS problems), security header problems, cookie security issues, and exposed sensitive information. It focuses on configuration vulnerabilities and security posture issues that can be detected through passive analysis.

Is vulnerability scanning safe for production environments?

Yes, our vulnerability scanner uses passive scanning techniques that are safe for production environments. We analyze publicly available information and use read-only methods. We never attempt to exploit vulnerabilities or perform actions that could harm your website or infrastructure.

Can I use this for compliance requirements?

Yes, vulnerability scanning is often required for compliance frameworks like PCI DSS, HIPAA, SOC 2, and ISO 27001. Our scanner provides evidence of security controls and can identify gaps in your security posture. Supplement with internal assessments and professional testing for complete compliance coverage.

What should I do if critical vulnerabilities are found?

If critical security issues are detected, prioritize immediate remediation. Apply configuration fixes, verify the remediation, and document the incident. For complex issues or if you're unsure about the fix, consider engaging security professionals for guidance. Critical configuration issues like missing security headers or weak TLS settings should be addressed within 24-48 hours.

How does this compare to other vulnerability scanners?

Our vulnerability scanner is free, non-intrusive, and provides instant results with actionable remediation guidance. It focuses on configuration vulnerabilities and security misconfigurations through passive analysis. For enterprise needs, consider combining our tool with commercial scanners and professional security assessments for comprehensive coverage.

Does the scanner work with APIs and web services?

Yes, our vulnerability scanner works with web applications, APIs, and web services. It analyzes security headers, CORS policies, TLS configuration, and other publicly accessible security configurations. For comprehensive API security testing, combine passive scanning with manual API security testing.
Why Barrion

Built for the engineers who already have enough to fix.

Speed

Fast results

Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage

Comprehensive checks

The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action

Step-by-step fixes

Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will our auditor or enterprise customer accept the report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we store the findings and the evidence behind them, the requests and responses that confirm each issue, so you can review and reproduce them. Test credentials you add are encrypted. Data is stored and hosted in Sweden and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

Keep it covered

Fix it once, then watch it stay fixed.

A pentest shows what is exploitable today. A scheduled passive scan re-checks this tool's results and alerts you when a deploy undoes the fix.

What you get for free

18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.

What Essential adds from €199/mo

Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.