What is Shieldome?
Shieldome is a web vulnerability and performance scanner built for security professionals and developers. It checks your websites against the OWASP Top 10 (2021) — the industry standard for web application security risks — and measures key performance metrics.
Every scan produces a detailed report with findings categorized by severity, evidence of each issue, and step-by-step remediation guidance. Reports can be exported as PDF, JSON, CSV, or SARIF.
Active detection, not exploitation
Shieldome sends probes to detect vulnerabilities by observing server behavior — it never exploits them, exfiltrates data, or causes lasting changes to your application.
Who is it for?
- Developers who want to catch security issues before deploying to production.
- Security teams running periodic assessments on their web properties.
- DevOps engineers integrating security checks into CI/CD pipelines via the REST API or CLI.
- Agencies scanning multiple client sites with batch jobs and white-label PDF reports.
Key features
- OWASP Top 10 coverage — 100+ checks across all 10 risk categories
- Performance analysis — DNS, TTFB, HTTP/2, compression, caching
- Real-time progress — live updates via Server-Sent Events (SSE)
- PDF reports — professional, detailed, ready to share
- Multiple export formats — JSON, CSV, SARIF for GitHub Advanced Security
- REST API & CLI — integrate with any pipeline
- Scheduled scans — automated recurring assessments
- Batch jobs — scan dozens of sites in one operation
- Scan history & trends — track improvements over time
Requirements
- A Shieldome account with at least 1 scan token (new accounts receive 1 free token on email verification)
- An authorized domain — you must own or have permission to scan the target
Only scan sites you own or have explicit written permission to test.
Scanning third-party sites without authorization may be illegal in your jurisdiction.
Advanced capabilities
Once you've completed your first scan, explore the more powerful features:
- Authenticated scanning — scan behind a login using cookies, tokens, or Playwright form login. The majority of real-world vulnerabilities only appear after authentication.
- SaaS domain monitoring — register your domains for automatic daily or weekly scans. Get email alerts the moment new vulnerabilities appear.
- Compliance posture — see how your scan results map to SOC 2, ISO 27001, GDPR, and PCI-DSS controls.
- Scan comparison — diff any two scans to track regressions and verify fixes.
- Scan profiles — save your scan settings as a named profile for one-click re-use.
- Triage & risk acceptance — review, annotate, and manage findings with your team.
- CSP Builder — interactively build and score your Content Security Policy.