Free · Instant · No sign-up

PCI Quick Check

Deep PCI Compliance Pre-scan with 44 Security Checks

Example: bing.com or 203.0.113.24

44 checks included in this free scan

Takes about 4 minutes to complete.

1.TLS/SSL Versions

Checks for outdated/vulnerable protocols like SSL 3.0, TLS 1.0, TLS 1.1.

2.SSL Certificate

Validity, expiration, chain trust, hostname match, key size, signature algorithm.

3.Security Headers

Reviews HSTS, X-Content-Type-Options, CSP, and Referrer-Policy hardening headers.

4.Insecure Server Configuration

Checks TRACE handling, version-banner disclosure, and exposed directory listings.

5.Open Ports

Maps common externally reachable services for business-need, patch, and authentication review.

6.Firewall Rules (Inferred)

Analyzes whether high-risk ports are properly restricted.

7.DNS Zone Transfer

Checks if AXFR zone transfers are allowed.

8.Vulnerable Software

Flags legacy-looking Apache, nginx, IIS, PHP, OpenSSL, and ASP.NET banners for version verification.

9.Sensitive Files Exposed

Publicly accessible files like web.config, .env, wp-config.php, phpinfo.php, backups, admin panels.

10.HTTP Security Issues

Reviews plaintext HTTP-to-HTTPS handling and literal mixed-content references.

11.Exposed Management Interfaces

phpMyAdmin, cPanel, Plesk, Webmin, WHM, DirectAdmin, WordPress admin, Tomcat, etc.

12.Exposed API Keys

Scans page source for leaked AWS, Google, Stripe, GitHub, Slack, SendGrid, Twilio keys, and private keys.

13.Clickjacking Protection

Verifies X-Frame-Options or CSP frame-ancestors prevent your site from being framed by attackers.

14.Cookie Security

Checks homepage cookies for applicable Secure, HttpOnly, SameSite, and cookie-prefix protections.

15.Error Disclosure

Probes for verbose error pages leaking stack traces, file paths, or framework internals.

16.Cloud Storage Exposure

Checks AWS S3, Google Cloud Storage, and Azure Blob containers advertised by the homepage for public listing.

17.OAuth/OIDC Security

Probes the OpenID Connect discovery endpoint for weak signing algorithms and missing PKCE support.

18.PII Detection

Flags non-test Luhn-valid PAN candidates and SSN patterns in sampled homepage source for manual validation.

19.Weak Cryptography

Detects references to MD5, SHA-1, DES, RC4, and insecure JS patterns like Math.random for tokens.

20.Admin Panel Discovery

Probes common admin paths (/admin, /wp-login, /manager, etc.) for exposed login forms that should be IP-restricted.

21.CORS Misconfiguration

Sends a foreign Origin header and distinguishes exploitable credentialed reflection from invalid or public CORS policies.

22.WebSocket Security

Scans page references for ws:// (unencrypted) versus wss:// (TLS) WebSocket endpoints. Plain ws:// traffic is readable on the wire.

23.CSRF Token Presence

Inspects POST forms on the homepage for a hidden anti-forgery token field. Forms without tokens may allow cross-site request forgery.

24.JSON Hijacking

Samples linked JSON/API endpoints for top-level arrays without anti-hijack guards - an older but still-exploitable class of bug.

25.SQL Injection Detection

Sends bounded, non-destructive quote probes to common GET parameters and checks for exposed database errors or new server failures.

26.Cross-Site Scripting (XSS) Detection

Uses bounded, non-executing HTML markers to detect common GET parameters that are reflected without output encoding.

27.Advanced SSL/TLS Vulnerability Testing

Targets POODLE, BEAST-era CBC, SWEET32, RC4, FREAK, NULL ciphers, CRIME compression, static RSA, and insecure renegotiation.

28.HTTP Parameter Pollution

Compares direct and duplicated GET parameters for validation bypasses, concatenation, inconsistent precedence, or new server errors.

29.Server-Side Request Forgery (SSRF)

Uses a controlled public HTTPS canary to detect URL parameters that fetch and return remote content server-side.

30.XML External Entity (XXE) Injection

Discovers public XML/SOAP processors and uses one controlled external HTTPS entity to test whether remote content is expanded.

31.Insecure Deserialization

Looks for exposed serialized object formats and deserializer-specific errors using non-executable GET probes.

32.OS Command Injection

Uses command-free expansion canaries and incomplete shell syntax to detect unsafe command processing.

33.Path Traversal

Uses the target's public robots.txt as a safe canary to test file-like GET inputs for directory traversal.

34.File Upload Security

Discovers public upload forms, methods, type hints, storage listings, and visible security controls without submitting a file.

35.LDAP Injection

Uses malformed, non-broadening LDAP filter and DN syntax to detect directory-service error leakage.

36.NoSQL Injection

Uses malformed, non-broadening data values to detect NoSQL database and query-parser error leakage.

37.Server-Side Template Injection (SSTI)

Uses side-effect-free arithmetic canaries to detect server-side template evaluation and engine-specific errors.

38.Business Logic Flaws

Passively reviews public forms and links for client-authoritative fields, mutable GET routes, and predictable sensitive identifiers.

39.Mass Assignment

Reviews public mutation forms and client scripts for privileged bindable fields, broad property containers, and risky object serialization.

40.SOAP Injection

Reviews SOAP/WSDL schemas and uses a uniquely named nonexistent operation to detect unsafe dispatch and verbose faults.

41.Open DNS Resolver / Recursive DNS Exposure

Confirms whether the target's DNS service resolves unrelated internet names for unauthenticated clients.

42.Dangerous HTTP Methods and WebDAV Exposure

Uses non-destructive OPTIONS and PROPFIND requests to detect exposed WebDAV collections and risky method advertisement.

43.Anonymous FTP + Cleartext Authentication

Checks FTP, Telnet, SMTP, POP3, and IMAP for anonymous access or credential flows exposed before transport encryption.

44.Exposed WebDAV / Backup / Deployment Artifacts

Uses soft-404 baselines plus binary and text signatures to find downloadable archives, backup configs, deployment files, source maps, and legacy WebDAV metadata.

Frequently asked questions about PCI compliance

Everything you need to know about our free PCI scanner and the wider PCI DSS standard.

What is PCI compliance?
PCI compliance means meeting the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements for any business that stores, processes, or transmits credit card data. Compliance is mandated by the major card brands (Visa, Mastercard, Amex, Discover, JCB) and is typically demonstrated by completing the appropriate Self-Assessment Questionnaire and, for most merchants, passing a quarterly external vulnerability scan.
Is this PCI scan really free?
Yes. The 44-check PCI Quick Check on pciscan.org is 100% free with no sign-up. We also offer paid services such as an Approved Scanning Vendor (ASV) report for merchants who need a formal compliance document.
How long does the scan take?
The online scan completes 44 checks in about 4 minutes, although the exact time depends on the target and network response times.
Is PCIScan an Approved Scanning Vendor (ASV)?
The free scanner is a pre-scan and educational tool, not an ASV report. We do offer a paid ASV scan service that produces a formal report you can submit to your acquiring bank or payment gateway.
What should I do if my scan fails?
Each failed check shows exactly what was found. Fix the underlying issues (renew the certificate, close unused ports, add the missing header, etc.) and re-run the scan. If you would like hands-on help, our Diagnose & Repair service troubleshoots and fixes the issues for you with a money-back guarantee.
Can I scan any website?
You may only scan domains or IP addresses you own or are explicitly authorised to test. Unauthorised scanning may breach computer-misuse laws.