Join 3,000+ companies securing their attack surface with Intruder

Catch credentials hiding in plain sight

Intruder filters out the false positives that bury most secret scanners, so you only see credentials that are actually exposed. Check your infrastructure and public-facing directories for the leaks worth acting on.

Get back the time you spend leak-hunting

Intruder runs continuous scans across your live environments, so checking for exposed credentials isn't your job anymore. That's hours back for the security work that actually needs a human.

See the secrets buried in your JavaScript

Front-end JavaScript is where the most damaging leaks tend to hide. Intruder spiders the JavaScript bundles behind your single-page applications and flags any exposed secrets.

Agentless onboarding

No agents to install. Point Intruder at your domains, IPs, and web apps, and it starts checking them for exposed secrets straight away, no configuration required.

Continuous scanning

Intruder checks your infrastructure, web apps, and JavaScript bundles against more than 850 token and key formats. Its Dynamic Application Security Testing (DAST) engine spiders your apps as they change.

Consolidated results

Every exposed credential shows up in one place, with what it is and where it leaked, so you can revoke and rotate it without hunting across tools.

Find what's exposed, fix what matters, and stay ahead of new threats

Can I scan single page applications (SPAs) with Intruder?

Yes, you can! Learn all about how to scan SPAs with Intruder here.

How do I scan my website for vulnerabilities with Intruder?

The first thing you need to do is add your website as a target by entering its IP address or url. You can then kick off your first scan in just a few clicks – it’s that simple!

What website security checks does Intruder perform?

Intruder’s website security scans check for web-layer security problems such as SQL injection and cross-site scripting, as well as other security misconfigurations. Read more about Intruder’s checks here. 

What do you mean by scanning your website, internally?

Your internal systems can be just as enticing to hackers as your external network so it’s important to test your website for vulnerabilities there too.

When we talk about scanning the website internally, we’re actually talking about scanning the web server that the website is hosted on. Web servers are internet-facing, but any sensitive information connected to them (such as databases) will sit behind a firewall, to prevent them from being reached by unauthorized individuals.

If ‘stuff’ can’t be reached externally, then remote checks won’t work and so you’d need to run local checks. At Intruder, all local/internal checks are performed via an agent which you’d install on the server.  

Internal vulnerability scanning also hunts through your website for missing patches and detects insecure versions of many thousands of software components and frameworks, including operating systems and network devices. Find out more about internal vulnerability scanning.

Can I scan my website if it is built using a CMS, such as WordPress?

Intruder works with many platforms, including WordPress, Drupal, Joomla, Squarespace and more.

Which plan should I choose if I just want to scan my website?

Choose our Essential or Cloud plan to externally scan your website. If you are looking at our internal vulnerability scanning capability, this is only available to our Pro and Enterprise customers. Visit our pricing page to learn more.

What license should I buy for a website that doesn’t have a login-page?

Buy any of our Essential or Pro plans that cover infrastructure licenses by default. Head to our pricing page for more information.