Web

Web applications security scanning

Dynamic application scanning powered by OWASP ZAP — spider, passive and active analysis.

How you connect

Add the URL and prove you control the domain. A1 Cloud Guard serves a verification file check before any scan runs, so you cannot point a scan at somebody else.

What A1 Cloud Guard looks for

  • Missing security headers and weak content security policy
  • Cookies without Secure, HttpOnly or SameSite
  • Injection and cross-site scripting candidates
  • Information disclosure in errors and responses
  • Outdated components with published advisories

1 service covered

Choose any combination per scan — you are never forced to scan the whole estate.

  • OWASP ZAP (Spider + Passive + Active)

Scan your Web estate

Connect a read-only credential and see the full report on the free plan.