Max Basev.
← All Projects
SaaSAI-powered

Scanwise

A passive website security scanner: DNS/SPF/DMARC, TLS, security headers, exposed secrets and config files, CORS/GraphQL checks, CVE lookup — with AI-generated remediation patches for what it finds. Free scans are live; paid AI reports are still being wired up (card payments turned out to be a story of their own).

🛡️ Scanwise — Passive Security Scanning + AI Fixes

🚀 About the Project

Scanwise runs a ~20-module passive recon pipeline against a domain — WHOIS, DNS, TLS, security headers, tech fingerprinting, subdomain enumeration, exposed secrets/config files, CORS/GraphQL checks, CVE lookup — and turns the raw output into severity-rated findings with an AI advisor for remediation.

🔍 What It Checks

DNS/SPF/DMARC, WHOIS and IP intel, TLS configuration

Security headers, CORS and GraphQL misconfigurations

Exposed secrets, .env/.git files, and other config leaks

Subdomain enumeration, port scanning, breach/threat intel

Tech fingerprinting and known CVEs for detected stack components

🎯 How It's Different

Fully passive and non-intrusive — built for authorized attack-surface monitoring, not active exploitation or pentesting. And it doesn't stop at a list of problems: an AI advisor turns each finding into a concrete remediation patch, so the report is something to act on, not just read.

📈 Tech Stack

Node.js + TypeScript backend (Express, MongoDB), Next.js frontend, GPT-4o for the remediation advisor and findings write-ups.

💳 Status

Free scans are live. Paid AI reports are still being wired up — payments turned out to be their own story, more on that later.

🔗 Visit

scanwise.dev

Follow the experiments.

Lab Notes — occasional emails when something ships. No schedule, no fluff.

Subscribe →