SECURITY
Free Security Check — Claw Score in 30 Seconds
Enter an IP, domain or URL: instantly see which risks are publicly visible — no registration, no agent, no waiting.
LIVE Security Check (Heuristic) — 30 Seconds
Enter an IP/domain/bot URL. You get a Claw Security Score + clear next steps.
Weekly Security Report
Critical CVEs, fix guides, and hardening tips — free, every week.
Mycelium Circle
Why teams use ClawGuru
Real score, not a marketing number
The Claw Score is based on real signals: open ports, missing headers, TLS weaknesses. No gamification, no fuzzing.
Fix runbooks right after the scan
Every finding links to a matching runbook with step-by-step instructions — no copy-paste from Stack Overflow.
GDPR-compliant & EU-hosted
No tracking, no data sharing. Scan targets are not stored permanently. Infrastructure in the EU.
How the Claw Score is calculated
The score aggregates publicly visible signals in four categories: TLS/HTTPS (25 pts), Security Headers (25 pts), Service Exposure (25 pts), and known CVE hits (25 pts). 100 = perfectly hardened, 0 = critically exposed.
Methodology & Limitations
This check evaluates publicly visible signals only (e.g. reachable services, header/TLS indicators, and common exposure patterns). Not a penetration test, no guarantee.
- • Score is heuristic and optimized for fast orientation.
- • For reliable conclusions, always verify configuration, logs, and internal scans.
- • Recommendations are designed for fast hardening execution via runbooks.
Harden further right away
Most common follow-ups after the check: concrete hardening guides for common stack components.
🚀 Further Resources
Security Check FAQ
Does ClawGuru store my inputs?
No. The check does not persist targets. Technically required request metadata can appear in server logs.
Is this a penetration test?
No. It is a fast heuristic evaluation of publicly visible signals. For binding conclusions, validate internally.
What should I do after the score?
Execute the top recommendations, harden with runbooks, then re-check for improvement.
What targets can I check?
IPv4 addresses, domains (e.g. example.com) and full URLs. The check automatically detects the type and selects the appropriate test modules.
How often can I check?
As a guest: unlimited for public targets. With an account: prioritised queue, scan history and automatic re-checks.