Focused security checks
Focused checks for deployed websites
Use focused website security checkers for public source maps, JavaScript secrets, exposed files, and deployment-platform signals.
- Account
- Not required
- Mode
- Passive
- Evidence
- Redacted
Choose a task
Start with the exposure you need to answer.
Each page prioritizes its matching result in the free preview. The scanner still reviews the wider public posture so you can see whether the focused issue sits inside a broader pattern.
Source map exposure checker
Test whether production JavaScript points to a reachable source map and review why it matters.
JavaScript secrets scanner
Review deployed bundles for secret-looking credentials with redacted evidence and false-positive guidance.
Exposed files checker
Check for publicly reachable environment files, repository metadata, backups, configuration, and debug output.
What these tools do
Confirm observable public signals.
SiteGuardrail requests public web resources, records the affected target, redacts sensitive-looking evidence, assigns a confidence level, and explains a practical remediation.
What they do not do
Prove that a site is secure.
Passive checks cannot validate private code, authorization on every endpoint, database policies, authenticated workflows, or issues that require exploitation. Missing coverage is reported as unknown rather than safe.