What is Shieldome?
Shieldome is a web vulnerability and performance scanner built for security professionals and developers. It checks your websites against the OWASP Top 10 (2021) - the industry standard for web application security risks - and measures key performance metrics.
Every scan produces a detailed report with findings categorized by severity, evidence of each issue, and step-by-step remediation guidance. Reports can be exported as PDF, JSON, CSV, or SARIF.
Active detection, not exploitation
Shieldome sends probes to detect vulnerabilities by observing server behavior - it never exploits them, exfiltrates data, or causes lasting changes to your application.
Who is it for?
- Developers who want to catch security issues before deploying to production.
- Security teams running periodic assessments on their web properties.
- DevOps engineers integrating security checks into CI/CD pipelines via the REST API or CLI.
- Agencies scanning multiple client sites with batch jobs and white-label PDF reports.
Key features
- OWASP Top 10 coverage - 100+ checks across all 10 risk categories
- Performance analysis - DNS, TTFB, HTTP/2, compression, caching
- Real-time progress - live updates via Server-Sent Events (SSE)
- PDF reports - professional, detailed, ready to share
- Multiple export formats - JSON, CSV, SARIF for GitHub Advanced Security
- REST API & CLI - integrate with any pipeline
- Scheduled scans - automated recurring assessments
- Batch jobs - scan dozens of sites in one operation
- Scan history & trends - track improvements over time
Requirements
- A Shieldome account (new accounts receive 1 free scan on email verification)
- An authorized domain - you must own or have permission to scan the target
Only scan sites you own or have explicit written permission to test.
Scanning third-party sites without authorization may be illegal in your jurisdiction.
Advanced capabilities
Once you've completed your first scan, explore the more powerful features:
- Authenticated scanning - scan behind a login using cookies, tokens, or Playwright form login. The majority of real-world vulnerabilities only appear after authentication.
- SaaS domain monitoring - register your domains for automatic daily or weekly scans. Get email alerts the moment new vulnerabilities appear.
- Compliance posture - see how your scan results map to SOC 2, ISO 27001, GDPR, and PCI-DSS controls.
- Scan comparison - diff any two scans to track regressions and verify fixes.
- Scan profiles - save your scan settings as a named profile for one-click re-use.
- Triage & risk acceptance - review, annotate, and manage findings with your team.
- CSP Builder - interactively build and score your Content Security Policy.