A free, passive external scan across TLS, headers, exposed services, information disclosure, and MCP / AI exposure. No intrusive testing — we observe only what is publicly reachable.
Scan counts update live. Certification record is Paying.co's, across US, Canada, Europe, LATAM and the Caribbean.
Every scan returns a grade, a score for each of the five families, and findings written out in full — what we detected, why it matters, how to fix it, and the PCI DSS requirement it maps to. This is a real report, not a summary of one.
The TLS endpoint did not return a Strict-Transport-Security header.
Without HSTS a browser will attempt the first connection over plaintext, leaving that request open to downgrade and interception before the redirect to HTTPS ever happens.
Set Strict-Transport-Security with a max-age of at least 180 days at the CDN or reverse proxy so it covers every response.
4.2.16.4.3
6 of 6 baseline security headers were not present.
Most standard security headers are missing at once. Individually minor, together this reads as no active security owner — the strongest signal that deeper gaps exist and that no one is maintaining the edge.
Adopt a baseline header set (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) at the CDN or reverse proxy so every response is covered by default.
6.4.32.2.1
More findings in the full report. Run a scan without an account to see your grade, every family score, and a sample finding in full. Sign in free to open the rest.
Scan your domain →AI agents connect to the world through MCP (Model Context Protocol) servers — the endpoints that expose an agent's tools: file access, database queries, internal APIs. An MCP server left reachable and unauthenticated is a direct path to those tools. Runtime platforms only see this from inside your cloud. flaw.co finds it from the outside, the way an attacker would, with nothing but your domain.
Probes your public surface for reachable MCP endpoints across common paths and subdomains.
Confirms whether each endpoint enforces authentication — or answers anyone who asks.
Deep scans catch endpoints that hand over their entire tool catalog with no credentials.
Included in every scan, free. No configuration — run a scan and the MCP / AI exposure check runs alongside TLS, headers, surface, and disclosure.