Skip to content
Security Scanning

Find vulnerabilities before attackers do

Automated security scanning powered by Nuclei. Detect CVEs, misconfigurations, and exposed secrets — delivered alongside your uptime data, not in a separate tool.

330+ edge locations
Multi-channel alerts
1 minute checks
1 asset downCheck asset status below

Total Assets

8

Monitored

Protected

6

All checks passing

Down

1

Failing checks

Reviewing

1

Active scan

Avg Uptime

99.97%

Last 30 days

Avg Latency

146ms

Fleet average

A

Security Score

96/100
2 Medium
What's affecting your score2 findings
PassingMedium

Assets

upsec.watch

https://upsec.watch

99.99%

Protected

api.upsec.watch

https://api.upsec.watch

99.97%

Protected

billing-worker

worker:billing-prod

99.94%

Reviewing

404.upsec.watch

https://404.upsec.watch

—

Down

Recent Events

404.upsec.watch12:44 UTC

404.upsec.watch is down (timeout)

api.upsec.watch12:38 UTC

api.upsec.watch recovered

cdn-proxy-0312:22 UTC

cdn-proxy-03 added to monitoring

upsec.watch12:15 UTC

Security scan completed — A grade

billing-worker11:58 UTC

2 medium findings detected

404.upsec.watch11:30 UTC

404.upsec.watch recovered

Domain Discovery

Scanning for subdomains…

Monitoring 7,634 user assets across 330+ edge locations
3 regions1 min cadence365d retention

CVE & vulnerability detection

Powered by Nuclei's 9,000+ community-driven templates. Detect critical CVEs, SQL injection vectors, XSS vulnerabilities, and exposed admin panels — automatically, on every scan cycle.

Tech stack fingerprinting

Identify every framework, CMS, server version, and third-party service running on your assets. Get alerted the moment your tech stack changes — a common early indicator of compromise.

Zero noise, real findings

We only run high-confidence templates that produce actionable results. No false-positive spam flooding your inbox. Every finding is a real issue with clear remediation steps.

Composite scoring

One grade. Complete picture.

After every scan, UpSec.Watch calculates a composite security grade from A+ to F — factoring in finding count, severity distribution, tech stack exposure, and known CVE impact. Track your grade over time to prove security improvement to stakeholders, clients, or compliance auditors.

  • A+ to F scoring based on severity-weighted findings analysis
  • Historical grade tracking — prove security improvement over time
  • Per-asset grades on your dashboard for instant portfolio overview
security-grade
Security Grade
0 critical
2 high
7 medium
31 info
Nuclei-powered

9,000+ templates. Zero false positives.

Our scanner runs Nuclei — the industry-standard open-source vulnerability scanner with 9,000+ community-maintained templates. But we only execute high-confidence templates that produce actionable results. No false-positive spam, no noise. Every finding is a real issue with clear remediation steps.

  • CVE detection, SQL injection, XSS, exposed admin panels — automated
  • Only high-confidence templates — zero false-positive noise
  • Community-updated templates catch newly disclosed CVEs within hours
nuclei-scan
[INF]Running nuclei v3.3.7
[INF]Templates loaded: 9,847
[CVE-2024-1234][critical]example.com/api
[exposed-panels][high]admin.example.com
[tech-detect][info]nginx/1.25.4
[INF]Scan completed: 3 findings
Tech intelligence

Know exactly what's running — and what changed

UpSec.Watch fingerprints every framework, CMS, server version, and third-party service on your assets. When your tech stack changes — a new Nginx version, a different CDN, an unexpected framework — you get alerted immediately. Tech stack changes are often the earliest indicator of compromise or unauthorized deployment.

  • Detect frameworks, servers, CDNs, and third-party services automatically
  • Instant alerts when technology versions change unexpectedly
  • Track version history — know exactly when each change happened
tech-detect
Detected technologies5 found
Nginx 1.25.4← was 1.24.0Server
React 18.3Framework
Node.js 20Runtime
CloudflareCDN
Let's EncryptCertificate

Enterprise-grade scanning, indie-friendly pricing

CVE vulnerability detection

Automatically test for thousands of known vulnerabilities across web applications, APIs, and server software using regularly updated Nuclei templates.

Technology fingerprinting

Detect frameworks (React, WordPress, Laravel), web servers (Nginx, Apache), and third-party services. Know exactly what's running — and what's exposed.

Misconfiguration scanning

Find open directories, debug endpoints, CORS misconfigurations, missing security headers, and default credentials before an attacker does.

Exposed secret detection

Scan for leaked API keys, database credentials, AWS tokens, and other secrets accidentally exposed in public-facing responses or error pages.

A–F security grade scoring

Get a single, glanceable grade for each asset. Track improvement over time with historical grade trends on your dashboard.

Scan history & trend tracking

Every scan is stored with full results. Compare findings across scans to verify fixes, catch regressions, and demonstrate compliance progress.

Daily and hourly automated scans

Set it and forget it. Scans run on your chosen schedule — daily for Plus/Pro, hourly for Team — with instant alerts when new vulnerabilities appear.

Actionable remediation guidance

Each finding includes severity rating, affected component, and clear fix instructions. No security expertise required — just follow the steps.

Start scanning in three steps

01

Add your website

Enter your domain or IP address and verify ownership with a DNS TXT record. Free-tier passive scans start immediately — no verification needed.

02

We scan with Nuclei

Our scanner runs thousands of security templates against your asset — checking for CVEs, misconfigurations, and exposed secrets on autopilot.

03

Review findings and fix

Get a prioritized list of vulnerabilities with severity grades and remediation steps. Fix the critical issues first, then work your way down.

9,000+

Scan templates

A–F

Security grades

Daily

Auto-scans

0

False positives

Frequently asked questions

Vulnerability scanning automatically checks your websites and servers for known security weaknesses — outdated software, misconfigurations, exposed credentials, and CVEs (Common Vulnerabilities and Exposures). Without regular scanning, you won't know you're vulnerable until an attacker finds the hole first. UpSec.Watch runs scans on autopilot so you're always aware of your security posture.

After each scan, we calculate a composite security grade from A+ (excellent) to F (critical risk). The grade factors in the number of findings, their severity (critical, high, medium, low, info), your tech stack exposure, and whether known CVEs affect your software versions. A is the goal — it means no critical or high findings and a hardened configuration. The grade updates after every scan so you can track improvement over time.

No. Our scanner is designed to be lightweight and non-intrusive. Free-tier scans use passive fingerprinting only — we analyze HTTP response headers and publicly visible metadata without sending aggressive requests. Paid-tier Nuclei scans use high-confidence templates that send minimal, targeted requests — not brute-force fuzzing. Your visitors won't notice a thing.

Free (Hobby) tier runs passive metadata scans (tech stack fingerprinting, SSL/TLS checks, and domain intelligence) automatically. You also get a limited vulnerability assessment — critical-severity-only scans you can trigger manually once a week, so you get a taste of what active scanning reveals. Plus unlocks full vulnerability assessment plus security misconfiguration detection, running daily. Pro adds exposure detection for open APIs and metadata leaks. Team tier adds hourly scan frequency and white-label PDF reports.

Yes. Active security scanning requires domain verification via a DNS TXT record or HTML file upload. This is a legal and ethical requirement — we only scan assets you own or are authorized to test. Passive tech-stack fingerprinting on the free tier does not require verification, since it only reads publicly available information.

It depends on your plan. Hobby (free) runs passive metadata scans every 6 hours automatically, plus you can trigger a manual critical-vulnerability scan once per week. Plus and Pro run full active scans daily — Plus covers vulnerability assessment and misconfiguration, Pro adds exposure detection. Team tier runs all modules hourly. You can also trigger a manual scan at any time from your asset detail page, selecting exactly which scan modules to run.