# Pentest Testing Corp — Free Website Security Scanner > A free online security scanner for websites. It performs 15 passive and semi-passive > checks across the external attack surface and maps every finding to SOC 2, PCI DSS, > and HIPAA controls. Operated by Pentest Testing Corp, a manual-led penetration testing > firm serving 250+ clients in 30+ countries. ## What the scanner checks - HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and more) - TLS/SSL configuration: certificate expiry, TLS version, cipher suite - HSTS and CSP quality (not just presence) - Exposed sensitive files across 22 paths (.env, .git, database dumps, admin panels) - Directory listing across common directories - Cookie security flags (Secure, HttpOnly, SameSite) - CORS misconfiguration via Origin reflection testing - Open redirects across common redirect parameters - Dangerous HTTP methods (TRACE, PUT, DELETE) - Email security: SPF and DMARC records - Information disclosure: error page leaks and suspicious HTML comments ## Compliance mapping Findings are mapped to SOC 2 Trust Services Criteria, PCI DSS v4.0 requirements, and HIPAA Security Rule sections, so teams preparing for an audit can see where they stand. ## Services offered by Pentest Testing Corp - Web application penetration testing - API penetration testing - Mobile application penetration testing - Cloud penetration testing - Internal network penetration testing - Compliance readiness: SOC 2, PCI DSS, HIPAA, ISO 27001, GDPR ## Key links - Free scanner: https://free.pentesttesting.com/ - Main site: https://www.pentesttesting.com/ - Pricing: https://www.pentesttesting.com/pricing/ - Book a scoping call: https://calendly.com/shofiur-pentesttesting/30min - Contact: https://www.pentesttesting.com/contact/ ## Note The free scan finds common misconfigurations. A manual penetration test by certified experts is required to find business-logic flaws and to produce attestation-ready evidence for compliance audits.