Your site has vulnerabilities.
Find them first.
Fast scan covers a limited set of checks. Sign up for full coverage and continuous monitoring.
40K+
Users worldwide
50M+
Scans completed
11K+
Security scanners
Latest added scans
SeverityScan nameAdded
HighGUDE 2301 and 2302 Default Credentials ScannerDetects 'Default Credentials' vulnerability in GUDE 2301 and 2302.
22 hours agoHighCaldera Detection ScannerIdentify the stealthy CALDERA within your network.
9 days agoMediumCaldera Forms Cross-Site Scripting (XSS) ScannerDetects 'Cross-Site Scripting (XSS)' vulnerability in Caldera Forms.
9 days agoCriticalGeneric Command Injection Vulnerability ScannerA command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.
15 days agoMediumCVE-2022-39258 ScannerCVE-2022-39258 Scanner - Cross-Site Scripting (XSS) vulnerability in Mailcow Dockerized
19 days agoEvery vulnerability.
Clearly explained.
app.s4e.io / scan-reports
Scan Reports
| Target | Port | Name | Severity | Status | Source | Last Detected | Action | |
|---|---|---|---|---|---|---|---|---|
| demo.s4e.io | 80 | SQL Injection | Critical | Open | Manual Scan | 15 Apr 2026 23:41 | ··· | |
| demo.s4e.io | 443 | Exposed .env file | Critical | Open | Continuous Scan | 15 Apr 2026 23:40 | ··· | |
| api.demo.s4e.io | 443 | Reflected XSS | High | Re-Opened | Continuous Scan | 15 Apr 2026 23:39 | ··· | |
| demo.s4e.io | 443 | Outdated jQuery CVE-2019-11358 | High | Open | Continuous Scan | 15 Apr 2026 23:38 | ··· | |
| admin.demo.s4e.io | 80 | Directory Listing Enabled | Medium | Open | Continuous Scan | 15 Apr 2026 23:37 | ··· | |
| demo.s4e.io | 443 | Missing HSTS Header | Medium | Open | Continuous Scan | 15 Apr 2026 23:36 | ··· | |
| demo.s4e.io | 443 | Subdomain Finder Online | Informational | Open | Continuous Scan | 15 Apr 2026 23:35 | ··· |
+39 more findings in the full report
This is what S4E.io found on a public demo domain in a few hours.
Scan your domain free →Security For Everyone.
Professional-grade security scanning accessible to all from solo developers to enterprise teams. No expertise required.
Free for all.
Start scanning immediately. No credit card, no account, no waiting.
14.000+ checks.
Open ports, CVEs, misconfigurations, exposed credentials the most comprehensive scan available.
Zero setup.
No agents. No config. No DevOps. Enter a domain and you're protected in seconds.
“
S4E.io found a SQL injection we'd had for 8 months.
We fixed it in an afternoon.
Our pentest company missed it entirely.
Alex K.CTO, SaaS Startup