Scanwise
A passive website security scanner: DNS/SPF/DMARC, TLS, security headers, exposed secrets and config files, CORS/GraphQL checks, CVE lookup — with AI-generated remediation patches for what it finds. Free scans are live; paid AI reports are still being wired up (card payments turned out to be a story of their own).
🛡️ Scanwise — Passive Security Scanning + AI Fixes
🚀 About the Project
Scanwise runs a ~20-module passive recon pipeline against a domain — WHOIS, DNS, TLS, security headers, tech fingerprinting, subdomain enumeration, exposed secrets/config files, CORS/GraphQL checks, CVE lookup — and turns the raw output into severity-rated findings with an AI advisor for remediation.
🔍 What It Checks
DNS/SPF/DMARC, WHOIS and IP intel, TLS configuration
Security headers, CORS and GraphQL misconfigurations
Exposed secrets, .env/.git files, and other config leaks
Subdomain enumeration, port scanning, breach/threat intel
Tech fingerprinting and known CVEs for detected stack components
🎯 How It's Different
Fully passive and non-intrusive — built for authorized attack-surface monitoring, not active exploitation or pentesting. And it doesn't stop at a list of problems: an AI advisor turns each finding into a concrete remediation patch, so the report is something to act on, not just read.
📈 Tech Stack
Node.js + TypeScript backend (Express, MongoDB), Next.js frontend, GPT-4o for the remediation advisor and findings write-ups.
💳 Status
Free scans are live. Paid AI reports are still being wired up — payments turned out to be their own story, more on that later.
🔗 Visit
scanwise.dev