Passive by default · nothing intrusive

Your attack surface is already public.You just haven't read it.

Every certificate you issue, header you omit, and dependency you ship is observable from outside your perimeter. Webcuris reads all of it continuously, ranks what an attacker would reach first, and tells you whether last month's fix actually held.

Free tier · no card required · passive checks only

DiscoverAssessClassifyPrioritiseVerify
webcuris.com/dashboard
Assets
12
Open findings
77
Critical
2
Fixed · 7 days
+9
Posture9 assessments
86
Posture / 100
050100Jun 2, 2026Jul 28, 2026
Fix first
  • Missing HTTP Strict-Transport-Security9 assetshigh
  • TLS 1.0 negotiated2 assetshigh
  • CSP allows unsafe-inline6 assetsmedium
  • SPF record missing1 assetmedium

The product's own dashboard components, rendered with a representative dataset — not a live account.

What every assessment reads

From nothing to a read surface in three steps.

No agents to install, no traffic to reroute. The first assessment is reading what you already publish.

01

Create an account

Free, no card. You get the same scanning engine as every paid plan — the tier changes scope, never quality.

Sign-up takes under a minute

02

Point it at a domain or repository

Passive external checks start immediately — the same requests a browser makes. Prove ownership with a DNS record and the deeper checks unlock.

Passive by default · nothing intrusive

03

Read, fix, verify

Every finding carries severity, confidence, and a remediation package. The next scan says whether your fix actually held.

Findings tracked across every scan

Two surfaces, read the same way.

What you expose to the internet and what you ship in your repositories are the same risk seen from two sides. Both get scanned, scored, and tracked in one history.

External checks are passive — the same requests a browser makes. Anything beyond that stays locked until you prove you own the domain.

External surface
HTTP response headers
HSTS, frame options, content-type, referrer policy
Content-Security-Policy
Directive analysis — unsafe-inline, wildcards, missing fallbacks
TLS & certificates
Protocol versions, chain trust, expiry, legacy negotiation
DNS hygiene
SPF, DMARC, CAA, DNSSEC signal
Cookies
Secure, HttpOnly, SameSite attributes
Mixed content
Insecure subresources on a secure page
Subdomains
Certificate Transparency log enumeration
Code surface
Dependencies
8 package ecosystems resolved against OSV.dev
Secrets
Credential patterns in source, masked before storage
Dockerfile
Root user, unpinned bases, baked secrets, unsafe ADD
Kubernetes
Privileged pods, capabilities, host namespaces, limits
Code patterns
eval, shell interpolation, SQL concatenation, weak hashes
LLM usage
Prompts built from request input, agents wired to shell

What's inside the engine.

Everything below is implemented and running today. Nothing on this page is a roadmap item wearing present tense.

Individual findings don't breach you. Paths do.

The correlation engine reads findings together — within a scan and across every asset you own — and names the compound risk no single row would have shown you.

No HSTSTLS 1.0 acceptedDowngrade & intercept

A lifecycle, not a list

Every finding is fingerprinted and tracked across scans: new, persisting, fixed — and regressed, counted every time it comes back.

Confidence on every row

Confirmed, strong indication, potential, informational. A scanner that states how sure it is lets you tell a fact from a pattern.

EPSS on dependencies

Public exploit-prediction scores on dependency findings, so “critical” and “actually being exploited” stay distinguishable.

Alerts that cannot mask each other

Email and webhooks — Slack, PagerDuty, Datadog, Splunk — fire independently from one decision. A failing webhook cannot suppress the email.

Four report types

Plus SBOM and JSON export for the tools that come after the read.

ExecutiveTechnicalComplianceAttestation

Your code calls models now.
That's attack surface too.

Prompts, agents, and the dependencies models hallucinate are read by the same engine, with the same severity-and-confidence discipline as every other finding.

AI usage, read from source

Code scan

Prompts assembled from request input, agents wired to shells, and secrets inside prompt templates are flagged where they live — in your repository.

finding · LLM prompt built from unsanitised request body · potential

Red-team checks for LLM endpoints

Web scan

Injection surface, system-prompt leakage, and tool abuse are exercised under the same authorization rules as every other check — passive until you prove ownership.

locked until domain ownership is verified

Hallucinated dependencies

Supply chain

Package names that models like to invent are checked against what actually exists in the registry. Slopsquatting is a supply-chain vector now; this is the check for it.

finding · dependency not present in registry · strong indication

Agents under guardrails

Platform

The platform's own agent sessions run with least privilege, and destructive actions stop at a human approval checkpoint that an API key cannot satisfy.

approval required · api-key actors cannot approve their own actions

Open one finding

A row is only useful if it survives being opened.

Any scanner can produce a list. This is what one row looks like all the way down — and the four questions it has to answer before it has earned your afternoon.

HighConfirmed9 assets affected

Missing HTTP Strict-Transport-Security (HSTS) header

app.example.com · headers · CWE-319

A check fired, and it says how sure it is.

Category

Response headers · CWE-319

What the check looks for

A Strict-Transport-Security header on every HTTPS response, with a max-age long enough to survive between visits.

Severity

High — exploitable, but needs the attacker on the network path.

Confidence

Confirmed — the header is absent in the response, not inferred.

Severity is how bad this is if exploited. Confidence is how certain the scanner is that it is real — a separate axis, printed on every row, so you can tell a fact from a pattern before you spend an afternoon on it.

One representative finding, with the wording this check actually emits — not a live account.

8
Package ecosystems
11
Check categories
5
Severity levels
4
Report types

What it doesn't do, in writing.

A security vendor that lists only strengths is asking you to do the discovery yourself. The Security Policy documents the limitations in the same detail as the capabilities.

Trust Center →

No SOC 2, ISO 27001, or third-party penetration test. Compliance mappings are situational context, not audit evidence.

Passive by default. Checks that go beyond a browser visit stay locked until domain ownership is proven by DNS record or hosted file.

Your data stays yours. Findings are exportable, and account deletion is self-service — no request queue, no retention you didn't choose.

Findings can be wrong. False positives and negatives both happen, which is exactly why confidence sits on every row.

Priced on how much you watch.

Every plan runs the same engine and the same checks. What changes is how many assets you cover.

Free
$0forever

Assess one thing properly.

  • 1 domain and 1 repository (intended limit, not yet enforced)
  • Every check the engine runs — nothing held back
  • AI/LLM usage risk detection on every code scan
See full plan
ProRecommended
$39per month

or $399/year — nearly 2 months free

Continuous assessment for a growing surface.

  • 5 domains and 4 repositories
  • Continuous monitoring on a schedule you set
  • Cross-asset correlation — credential reuse, chronic regression
See full plan
Business
$79per month

or $799/year — nearly 2 months free

The whole portfolio, watched together.

  • 12 domains and 12 repositories
  • Everything in Pro
  • Compliance mapping: OWASP, NIST 800-53, CIS v8, ISO 27001, SOC 2
See full plan

Asked, answered.

The questions people arrive with — including the ones about what this deliberately refuses to do.

A passive scan only makes requests an ordinary visitor's browser would make: fetching pages, reading response headers, resolving DNS and inspecting published JavaScript. It sends nothing designed to change the target's behaviour, so it can be run against a site without prior arrangement. Active checks — which send requests a visitor would not — require proven ownership of the domain.

Find out what you're publishing.

Run an assessment against a domain you own and read the result in a few minutes. Free tier, no card, nothing intrusive.

Passive checks only · prove ownership to go deeper

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Prefer email?
Use the form — no address is published on this deployment.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000