AI ClicksScan · Detect · Secure
Standards-graded security intelligence

Scan any website. Get findings graded to CVSS, CWE & OWASP.

Live probes for TLS, security headers, DNS, and known CVEs — plus authorized XSS, SQLi, and SSRF testing on domains you verify. Every finding shows its evidence, severity, and fix. No black-box scores.

🎯CVSS 3.1 severity🛡Live CVE feedActive testing🤖AI · Quantum · GEO
Deep scan: Pro plan →
Create free account·Sign in·3 free instant scans left today

Paste a URL above and hit Scan →

Full Scan · Instant scan returns in ~5 seconds

TLS · DMARC · DNSSECAI content detectionBlockchain intelligenceGEO / llms.txt
Example findings · CVSS-graded
CRIT
SQL injectionCWE-89 · A03
9.8
HIGH
Component with known CVECVE-2021-23017
7.7
HIGH
Email anti-spoofing gapCWE-290 · A07
8.2
MED
Missing security headersCWE-693 · A05
5.4
LOW
Cookies missing attributesCWE-1004 · A05
3.1

What we scan

Every signal, fully transparent

Six independent modules. Each returns its own score, raw evidence, and fix recommendations.

Security Assessment

TLS & cipher grade, security headers, DNS/email posture (SPF, DKIM, DMARC, DNSSEC), cookies, and exposure — every finding scored to CVSS 3.1, CWE, and OWASP.

CVE Intelligence

Detected components are matched against a curated knowledge base and the live OSV feed — real CVE ids, CVSS, and the version that fixes them.

Active Testing

On domains you verify: authorized, non-destructive probes for reflected XSS, SQL injection, path traversal, open redirect, and out-of-band SSRF.

AI Detection

Perplexity, entropy, burstiness, lexical diversity, and phrase signals — transparent, per-signal scoring, not a single opaque number.

Quantum Readiness

Post-quantum cryptography posture checked against NIST PQC migration requirements.

GEO Visibility

AI search citation readiness: structured data, Open Graph, and canonical signals scored for ChatGPT and Perplexity.

Who uses it

Built for teams that need real evidence

🛡

Brand Safety Teams

Verify advertiser landing pages for AI-generated content, flagged phrases, and schema completeness before campaign spend.

🔐

Security Engineers

TLS, header, DNS, and CVE audit with CVSS-graded findings mapped to CWE and OWASP — plus authorized active testing on domains you verify.

📡

SEO & GEO Teams

Score structured data coverage, llms.txt adoption, and AI crawler access across competitor and client domains.

Developers & APIs

POST /api/v1/scans/url. Structured JSON with module scores, checks, signals, evidence strings, and recommendations.

How it works

Scan in three steps

Step 01

Enter a URL

Paste any public URL. We handle SSRF safety checks automatically before touching the target.

Step 02

Choose depth

Instant for quick public evidence or Deep for multi-page scanning and fuller reporting.

Step 03

Get your report

Structured JSON or interactive report with module scores, raw evidence, and fix recommendations.

Start scanning for free — no credit card required

5 free scans a day with an account. Deep scans on Pro, active testing on Advanced. Results in seconds.

Create free accountRun a scan now

FAQ

Common questions

TLS and cipher configuration, certificate validation, HTTP security headers, DNS and email posture (SPF, DKIM, DMARC, DNSSEC, CAA), cookie hygiene, sensitive-file exposure, subdomain-takeover risk, and known CVEs in detected components. Every finding is scored to CVSS 3.1 and mapped to CWE and OWASP Top 10.

On domains you have verified you own, AIClicks runs authorized, non-destructive tests for reflected XSS, SQL injection, path traversal, open redirect, and out-of-band SSRF. It is available on the Advanced plan and never runs on a domain you haven't verified.

No. Every finding shows its raw evidence, the CVSS 3.1 vector it was scored from, the CWE and OWASP references, and remediation steps — so you or an auditor can verify it independently.

Text perplexity via bigram KL-divergence against an English frequency model, Shannon entropy, sentence burstiness, lexical diversity, em-dash density, known AI marketing phrases, and Flesch-Kincaid grade level — each reported individually, not as one opaque number. It is probabilistic evidence, not legal proof.

Yes. POST /api/v1/scans/url with a URL and mode (instant or deep) returns a structured JSON report with modules, checks, findings, signals, evidence, and recommendations. Bulk API access is part of the Enterprise plan.