Amuneth Exposure

Security scans that first make visible what can go wrong.

At Amuneth we understand that security is a difficult subject for many organisations. Not because people do not think it matters, but because the reality is often complicated. There are websites, webshops, CMS systems, plug-ins, Microsoft 365 settings, suppliers, administrators, external agencies and old choices that all influence security. Meanwhile attackers move faster and faster, and entrepreneurs, schools, healthcare organisations, associations and small and medium-sized businesses face questions that can feel highly technical: is my website configured properly, are my accounts protected, is my WordPress installation safe, is my Drupal environment patched, or is something open in my tenant that I cannot see?

With Amuneth Exposure we want to lower that threshold. Our scanners are built to provide clarity first, not to sell fear. We want to show what is visible, what may create risk and which step logically follows. We do that in plain language, with clear priority and with attention to practice. A finding should not only be technically correct, but also understandable for the person who needs to act on it. That is why our people work every day on the scans, the checks, the explanation and the follow-up. We improve measurements, sharpen detection, process new vulnerabilities and translate technical signals into advice an organisation can actually use.

For us this is also a social responsibility. Digital security should not be a subject that is only accessible to organisations with large budgets or complete security teams. Everyone who depends on online services deserves a fair chance to recognise basic risks before they are abused. That is why we offer several scans for free and deliberately keep the first steps accessible. Where deeper analysis, manual review or hands-on help is needed, we make that clear. We believe in transparency: you should be able to see in advance what is free, where a paid step begins and why that step adds value.

At the same time, we take trust seriously. Scanning comes with responsibility. We want to prevent someone from assessing another person's website, webshop or environment without permission. That is why every visitor can calmly review which scans are available on this page, but running scans is only possible after creating a free account and signing in. This lets us link results to the right user, record permission and ownership properly and keep a safe history of what has been performed. For website, CMS and framework scans we also require ownership verification, for example through a DNS TXT record or a verification file on the website.

That approach fits what Amuneth stands for: careful, explainable and honest. We want to help organisations create calm instead of more noise. A scan is not an endpoint for us, but a starting point for better choices. Sometimes the advice is simple: update a plug-in, set a header correctly, close an unnecessary function or check a setting. Sometimes more is needed, and a deeper scan or guidance can help reduce risks structurally. In both cases the line stays the same: first insight, then priority, only then action.

Amuneth Exposure is therefore not a loose collection of technical tools, but an environment that grows step by step with the risks we see in practice. New vulnerabilities, widely used platforms and recurring mistakes are included in our scan routes. This creates a living environment that helps organisations understand where they stand faster, without immediately getting stuck in jargon or expensive projects. Create a free account, sign in and use the scans for environments you own or for which you demonstrably have permission. We will make sure the insights remain clear, useful and carefully stored.

Scan catalogue

All exposure scans in one place.

Choose the scan that matches your environment. Free scans remain free; paid deeper scans are clearly shown as separate steps.

Drupal Free

Drupal SQL injection risk scan

A safe check for Drupal sites for signals linked to known SQL injection risks, vulnerable Drupal core versions, public changelog signals and configuration indicators. The scan does not attempt exploitation.

  • Ownership verification through DNS TXT or verification file before the scan starts.
  • Advice on Drupal core updates, database profile, WAF rules, logging and incident checks.
  • Useful as quick triage during serious Drupal advisories.
Shopify Free

Shopify storefront security scan

A safe deep dive for Shopify webshops. The scan reviews storefront fingerprints, theme and app signals, product and collection endpoints, account/cart/checkout routes, policies, tracking, headers and third-party scripts.

  • Ownership verification before storefront, app and endpoint inventory is performed.
  • No Shopify admin access, login attempts or checkout actions.
  • Advice on app governance, theme code, customer accounts, tracking/consent and checkout integrations.
WordPress Free

WordPress vulnerability and plugin inventory

An inventory for WordPress site owners. The scan tries to determine WordPress version, visible themes, plugins, REST signals and hardening status, then translates that into concrete improvement points.

  • Ownership verification before plugin and theme inventory is performed.
  • Checks visible plugin paths, readme signals, XML-RPC, REST exposure and login hardening.
  • Advice for updates, plugin reduction, backups, MFA and management process.
Approach

Permission, report and follow-up remain clearly separated.

1

Login or account

Scans only run behind login, so we know who starts the scan and where the report should remain available.

2

Ownership check

For website, CMS and framework scans we require DNS TXT or a verification file before the scan runs.

3

Report and action

The report shows findings, risk, practical tips and, where needed, the route to deeper analysis or hands-on help.