Docs
← Home Sign In Get Started

What is Shieldome?

Shieldome is a web vulnerability and performance scanner built for security professionals and developers. It checks your websites against the OWASP Top 10 (2021) - the industry standard for web application security risks - and measures key performance metrics.

Every scan produces a detailed report with findings categorized by severity, evidence of each issue, and step-by-step remediation guidance. Reports can be exported as PDF, JSON, CSV, or SARIF.

🛡️
Active detection, not exploitation Shieldome sends probes to detect vulnerabilities by observing server behavior - it never exploits them, exfiltrates data, or causes lasting changes to your application.

Who is it for?

  • Developers who want to catch security issues before deploying to production.
  • Security teams running periodic assessments on their web properties.
  • DevOps engineers integrating security checks into CI/CD pipelines via the REST API or CLI.
  • Agencies scanning multiple client sites with batch jobs and white-label PDF reports.

Key features

  • OWASP Top 10 coverage - 100+ checks across all 10 risk categories
  • Performance analysis - DNS, TTFB, HTTP/2, compression, caching
  • Real-time progress - live updates via Server-Sent Events (SSE)
  • PDF reports - professional, detailed, ready to share
  • Multiple export formats - JSON, CSV, SARIF for GitHub Advanced Security
  • REST API & CLI - integrate with any pipeline
  • Scheduled scans - automated recurring assessments
  • Batch jobs - scan dozens of sites in one operation
  • Scan history & trends - track improvements over time

Requirements

  • A Shieldome account (new accounts receive 1 free scan on email verification)
  • An authorized domain - you must own or have permission to scan the target
⚠️
Only scan sites you own or have explicit written permission to test. Scanning third-party sites without authorization may be illegal in your jurisdiction.

Advanced capabilities

Once you've completed your first scan, explore the more powerful features:

  • Authenticated scanning - scan behind a login using cookies, tokens, or Playwright form login. The majority of real-world vulnerabilities only appear after authentication.
  • SaaS domain monitoring - register your domains for automatic daily or weekly scans. Get email alerts the moment new vulnerabilities appear.
  • Compliance posture - see how your scan results map to SOC 2, ISO 27001, GDPR, and PCI-DSS controls.
  • Scan comparison - diff any two scans to track regressions and verify fixes.
  • Scan profiles - save your scan settings as a named profile for one-click re-use.
  • Triage & risk acceptance - review, annotate, and manage findings with your team.
  • CSP Builder - interactively build and score your Content Security Policy.