Free passive scan

Free WAF Checker & Web Application Firewall Detection Tool

Free tool

Detects which WAF or CDN sits in front of your site from the signatures in a normal HTTPS response: headers like CF-Ray or X-Sucuri-ID, cookies like __cf_bm, and Server or Via banners. No attack payloads, no challenge pages triggered.

  • WAF/CDN detection from response headers, cookies and banners
  • Names the provider and the signals it matched
  • Security headers and TLS graded in the same run
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

What you get for free

18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.

What Essential adds from €199/mo

Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.

What this scan checks

WAF/CDN detection:
  • Provider headers (CF-Ray, X-Amz-Cf-Id, X-Sucuri-ID, X-Azure-Ref and more)
  • Provider cookies (__cf_bm, incap_ses_, BIGipServer, AWSALB and more)
  • Server and Via banners (cloudflare, AkamaiGHost, CloudFront, Vercel)
In the same run:
  • Security headers, TLS and cookie settings
Limitations:
  • No signature doesn't mean no WAF: providers can be set to strip their headers
  • Cannot detect WAF rules, rate limiting, or bot protection mechanisms
  • Cannot test challenge pages or active protection features
  • A detected provider may only be caching, with no WAF rules enabled

Why WAF checking matters

Verifying your WAF configuration helps ensure your website is properly protected. This tool helps you:

  • Identify your edge provider: See which WAF or CDN the response points to, and the signals it was matched on
  • Catch a bypassed edge: A site you expect behind a WAF that shows no signature may be served straight from its origin
  • Check security headers and TLS: The same scan grades headers, TLS and cookies

For WAF configuration, rule testing and active protection checks, use your WAF management console or a penetration test.

How Barrion verifies this

Barrion loads your site once, like a normal visitor, and reads the response it gets back. No challenge pages are triggered and no attack payloads are sent.

The WAF/CDN check matches that response against known provider signatures: headers such as CF-Ray, X-Amz-Cf-Id, X-Sucuri-ID, X-Iinfo or X-Akamai-*, cookies such as __cf_bm, incap_ses_ or BIGipServer, and Server or Via banners. The result names every provider it matched and the signals behind each one.

It covers Cloudflare, Akamai, Amazon CloudFront, AWS WAF and Elastic Load Balancing, Fastly, Imperva, Sucuri, F5 BIG-IP, Azure Front Door, Google Cloud Load Balancing, Vercel, Netlify and Barracuda. The same run also grades your security headers, TLS and cookies.

A match shows the provider is in the request path. It doesn't show which WAF rules are on, rate-limit thresholds, bot management or whether the WAF blocks or only logs. Check those in your WAF console.

What to do with WAF check results

After checking your WAF protection, use the results to improve your security:

  • Provider detected: Confirm in its console that WAF rules are enabled for this domain, not just caching
  • None detected but you use one: Check that the hostname's DNS points at the provider, or whether it strips its headers
  • Check WAF configuration: Review WAF rules and settings in your WAF platform (Cloudflare, AWS WAF, etc.)
  • Review security headers: Ensure security headers are properly configured
  • If you have no WAF: Consider adding one if your site handles sensitive data

Note: This tool detects a provider from response signatures only. For WAF rule configuration, rate limiting, bot protection, and active security testing, use your WAF management console or professional security assessments.

Tool-specific questions

What is a Web Application Firewall (WAF)?

A WAF is a security solution that filters, monitors, and blocks HTTP/HTTPS traffic to and from web applications. It protects against common attacks like SQL injection, XSS, and DDoS. WAFs can be cloud-based (like Cloudflare, AWS WAF) or on-premise solutions.

Does this tool detect my WAF?

Usually, if it leaves signatures in the response. The check looks for provider headers (CF-Ray, X-Amz-Cf-Id, X-Sucuri-ID), cookies (__cf_bm, incap_ses_, BIGipServer) and Server or Via banners, and names each provider it matches. Some setups strip these, so no match doesn't prove there's no WAF. We don't send attack payloads, trigger challenge pages or test rate limiting.

What's the difference between a WAF and a regular firewall?

A regular firewall filters network traffic at the network layer, while a WAF operates at the application layer (HTTP/HTTPS). WAFs understand web application protocols and can detect and block application-specific attacks like SQL injection and XSS, while regular firewalls focus on network-level threats.

Do I need a WAF if I have other security controls?

WAFs provide an additional layer of defense and are recommended for production websites. They complement other security controls like security headers, TLS configuration, and secure coding practices. WAFs are especially valuable for protecting against automated attacks and zero-day vulnerabilities.

What are challenge pages and why do WAFs use them?

Challenge pages (like CAPTCHA or JavaScript challenges) are used by WAFs to verify that requests come from real browsers rather than bots. However, our tool uses passive header analysis and cannot detect challenge pages, as they would require active testing to trigger. To verify challenge page functionality, test your WAF directly or review WAF logs.

How do I know if my WAF is working correctly?

Review WAF logs in your WAF management console, monitor false positive rates, and test your WAF with known attack patterns. This tool doesn't test rule configuration or effectiveness.

What should I do if I don't have a WAF?

If your site handles sensitive data, consider adding one. Cloud-based WAFs like Cloudflare, AWS WAF, or Akamai are easy to deploy, and on-premise options exist too.

Can this tool help with WAF configuration?

Not directly. It tells you which provider sits in front of the site. Rule configuration needs your WAF management console.

Is WAF protection required for compliance?

Many compliance frameworks (PCI DSS, SOC 2, ISO 27001) recommend or require WAF protection for web applications handling sensitive data. Your WAF console is the better evidence of WAF protection for an audit.
Why Barrion

Built for the engineers who already have enough to fix.

Speed

Fast results

Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage

Comprehensive checks

The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action

Step-by-step fixes

Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will our auditor or enterprise customer accept the report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we store the findings and the evidence behind them, the requests and responses that confirm each issue, so you can review and reproduce them. Test credentials you add are encrypted. Data is stored and hosted in Sweden and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.