About · est. 2026

The tool everyone used went dark.

In April 2026 SecurityHeaders.com switched off its public API. Thousands of pentesters and developers lost the one free thing that checked headers programmatically. What replaced it was either an enterprise SaaS contract or a half-maintained repo. SecureScanr is what I built instead — for my own client work first, then for everyone else's.

01 / The record

What actually happened

Apr 2026
SecurityHeaders.com shuts down its public API

The default free header checker stops being scriptable. CI pipelines and client-report workflows built on it stop working.

Apr 2026
Built as a personal tool

A scanner I needed for my own pentest deliverables: headers, plus the things a header checker never covered — TLS, DNS email security, cookies.

May 2026
SecureScanr goes live

Fourteen dimensions, an A–F grade, and the exact fix for every failing check. It scores B 78/100 on its own scan — the remaining gaps are listed in the methodology, not hidden.

02 / Who built it

No VC funding, no team, no growth hacks. One person who needed the tool.

Abhishek Patel Freelance pentester & developer · India

I built SecureScanr because I needed it for client work, and because the alternatives either cost more than the job paid or demanded an account and a credit card before showing a single result.

It stays a solo project. That is a constraint, not a pitch: it means the scoring is one person's published arithmetic, the roadmap is short, and every email reaches the person who wrote the scanner.

03 / The terms

What it is, and what it isn't

No login to scan

Free scans need no account, no email, no API key. Paste a URL.

Stateless by design

Scan results aren't stored. The only things kept are API keys and quota for Pro subscribers.

Published scoring

Every deduction is listed on the methodology page. Re-run a scan and the arithmetic is identical.

Priced in INR

India pays in rupees via Razorpay; everywhere else in USD. No conversion charges to work around.

Not a penetration test

It measures hardening, not exploitability. SQL injection, broken auth and logic flaws are out of scope.

Not a monitoring platform

Scans run when asked. Scheduled scanning across client domains is the Agency tier, not the default.

04 / The stack

Boring on purpose

Python Flask WeasyPrint SQLite Railway Cloudflare Pages

Vanilla HTML, CSS and JavaScript on the front — no framework, no build step

05 / Contact

Found a bug? Tell me.

Email

hello@securescanr.com

Bugs, feature requests, or a scan that returned the wrong result — I read every message.

API access & PDF export

Plans →

Checkout routes automatically to the right payment option for your location.

Scan your site free →