Every check we run. All 33 of them.
Free scanners fetch one page and grade its headers. vas tests your running app: database policies, auth flows, APIs, secrets, and the rest of what actually leaks customer data. Here is the complete list.
Every plan runs every check below. Plans differ in scan quota, deep scans, and monitoring, not coverage. See pricing
Security
The core of every scan. These checks test your running app the way an attacker would: your database policies, your auth endpoints, your APIs, and the JavaScript you ship to every visitor.
Database and backend
Database Security
Tests Supabase, Firebase, Convex, MongoDB, and PostgreSQL configurations with your own public keys to find tables and collections a stranger could read or write.
API Data Exposure
Detects unauthenticated APIs exposing PII, credentials, financial data, and other sensitive information.
SQL Injection Detection
Tests API endpoints and forms for SQL injection vulnerabilities using safe detection payloads.
GraphQL Security
Finds GraphQL endpoints and tests them for introspection exposure, field-suggestion leakage, query batching, and unauthenticated access to sensitive data.
tRPC Security
Discovers and probes tRPC endpoints for authentication bypass, admin access, and information disclosure.
ORM Security
Checks for Prisma and Drizzle ORM misconfigurations, exposed schemas, and client-side usage.
Authentication and access control
Authentication Security
Checks authentication endpoints, analyzes auth patterns, and evaluates how your login flow holds up.
Authenticated Testing (Pro deep scan)
Logs into your app with a test account and tests for IDOR, broken access control, and privilege escalation: can one user reach another user's data?
Password Policy
Tests password complexity requirements on Supabase, Firebase, or generic signup endpoints.
JWT Weakness
Tests whether your session tokens can be forged using common AI-generated secrets like "supersecretjwt".
Rate Limit Detection
Detects missing or weak rate limiting on auth and API endpoints that leaves you open to brute force and abuse.
Secrets and exposed code
Secrets Scanner
Scans your HTML source, JavaScript bundles, and discovered pages for exposed API keys and secrets, with 150+ patterns for OpenAI, Anthropic, Stripe, AWS, and more.
Payment Platform Security
Detects exposed payment secrets for Stripe, Paddle, LemonSqueezy, Polar, and Dodo Payments.
Exposed Files
Checks for exposed configuration files, .env files, .git folders, and other sensitive paths reachable from the web.
Source Map Exposure
Detects publicly downloadable JavaScript source maps (.js.map) that reveal your original source code, internal logic, and secrets.
Vulnerable Dependencies
Detects known-vulnerable versions of common front-end libraries (jQuery, Lodash, Moment, Axios, Bootstrap, AngularJS, Next.js) in your served bundles and flags published CVEs.
Headers, transport, and configuration
HTTP Security Headers
Analyzes HTTP headers for security misconfigurations: HSTS, CSP, X-Frame-Options, and the rest.
SSL/TLS Security
Checks SSL certificates, TLS versions, cipher suites, and mixed content.
Security Misconfiguration
Detects CORS misconfigurations, debug mode left on, WebSocket security issues, third-party script risks, and browser storage abuse.
Client-Side Security
Analyzes client-side JavaScript for XSS sinks, postMessage vulnerabilities, prototype pollution, and template injection.
Form Security
Analyzes discovered forms for CSRF protection, autocomplete settings, and secure transmission.
Platform-aware checks
Platform Fingerprinting
Identifies your hosting platform, framework, and AI code generation tool so every other check can apply platform-specific tests and fixes.
Crawler
Discovers URLs, forms, API endpoints, and technologies via browser-based crawling, so checks run across your app rather than one page.
AI/LLM Security
Detects AI integrations, MCP servers, and LLM tool misconfigurations.
Netlify Security
Checks Netlify Functions, Edge Functions, Identity, deploy previews, and platform-specific vulnerabilities.
Bubble.io Security
Checks Bubble Data API exposure, Workflow API, privacy rules, and platform-specific misconfigurations.
Email and identity monitoring
Email Security
Checks SPF and DMARC DNS records to assess whether attackers can spoof email from your domain.
Breach Monitoring (Pro)
Checks whether your email appears in known data breaches via Have I Been Pwned, and keeps watching.
SEO
A vulnerable app is one problem. An invisible one is another. Every scan includes on-page SEO health.
SEO Health
Passive on-page SEO checks: title, meta description, canonical, H1, Open Graph, JSON-LD, noindex, plus robots.txt and sitemap presence.
AI search readiness (AEO/GEO)
More buyers ask ChatGPT and Perplexity than ever. These checks tell you whether AI answer engines can see and cite your app.
AI Visibility (AEO/GEO)
Checks AI answer-engine visibility: llms.txt presence, robots.txt rules for AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended), JSON-LD structured data, and meta description.
Accessibility
Basic accessibility failures cost you users and, in some markets, invite legal risk.
Accessibility
Checks WCAG basics: page language, zoom disabled, missing image alt text, unlabeled form inputs, icon-only buttons and links, and heading structure.
Compliance
The legal basics AI tools routinely skip when they generate your app.
Compliance
Checks legal presence: privacy policy, terms of service, cookie consent when trackers are present, and security.txt (RFC 9116).
Performance
Slow apps lose customers before security ever matters.
Performance
Lightweight performance checks: server response time (TTFB), text compression, static asset caching, render-blocking resources, large images, and oversized DOM.
The deep scan goes where quick scanners can't
On the Pro plan, a weekly deep scan logs into your app with a test account and tries to reach other users' data across up to 150 pages: IDOR, broken access control, and privilege escalation. That is the class of bug that turns into a breach headline, and no header check will ever find it.
Compare plansSee what all 33 checks find on your app
Your first scan is free. Full coverage, results in 2-3 minutes, no card required.