Docs
← Home Sign In Get Started

What is Shieldome?

Shieldome is a web vulnerability and performance scanner built for security professionals and developers. It checks your websites against the OWASP Top 10 (2021) — the industry standard for web application security risks — and measures key performance metrics.

Every scan produces a detailed report with findings categorized by severity, evidence of each issue, and step-by-step remediation guidance. Reports can be exported as PDF, JSON, CSV, or SARIF.

🛡️
Active detection, not exploitation Shieldome sends probes to detect vulnerabilities by observing server behavior — it never exploits them, exfiltrates data, or causes lasting changes to your application.

Who is it for?

  • Developers who want to catch security issues before deploying to production.
  • Security teams running periodic assessments on their web properties.
  • DevOps engineers integrating security checks into CI/CD pipelines via the REST API or CLI.
  • Agencies scanning multiple client sites with batch jobs and white-label PDF reports.

Key features

  • OWASP Top 10 coverage — 100+ checks across all 10 risk categories
  • Performance analysis — DNS, TTFB, HTTP/2, compression, caching
  • Real-time progress — live updates via Server-Sent Events (SSE)
  • PDF reports — professional, detailed, ready to share
  • Multiple export formats — JSON, CSV, SARIF for GitHub Advanced Security
  • REST API & CLI — integrate with any pipeline
  • Scheduled scans — automated recurring assessments
  • Batch jobs — scan dozens of sites in one operation
  • Scan history & trends — track improvements over time

Requirements

  • A Shieldome account with at least 1 scan token (new accounts receive 1 free token on email verification)
  • An authorized domain — you must own or have permission to scan the target
⚠️
Only scan sites you own or have explicit written permission to test. Scanning third-party sites without authorization may be illegal in your jurisdiction.

Advanced capabilities

Once you've completed your first scan, explore the more powerful features:

  • Authenticated scanning — scan behind a login using cookies, tokens, or Playwright form login. The majority of real-world vulnerabilities only appear after authentication.
  • SaaS domain monitoring — register your domains for automatic daily or weekly scans. Get email alerts the moment new vulnerabilities appear.
  • Compliance posture — see how your scan results map to SOC 2, ISO 27001, GDPR, and PCI-DSS controls.
  • Scan comparison — diff any two scans to track regressions and verify fixes.
  • Scan profiles — save your scan settings as a named profile for one-click re-use.
  • Triage & risk acceptance — review, annotate, and manage findings with your team.
  • CSP Builder — interactively build and score your Content Security Policy.