What types of vulnerabilities does AI QA Monkey scan for?
AI QA Monkey performs comprehensive external security audits, detecting SSL/TLS issues, open ports, sensitive file exposure (.env, .git), security header misconfigurations, CORS risks, API endpoint discovery, subdomain takeover, and cloud storage exposure. It also includes specialized checks for WordPress, Shopify, React, and Node.js applications.
Is the security scan truly free, and what does it include?
Yes, the basic security scan is 100% free with no signup or credit card required. It covers SSL checks, port scanning, file leak detection, and header analysis. A premium full report with interactive attack surface visualization, detailed remediation code, and compliance mapping is available for a one-time fee of $29.
How does AI QA Monkey provide remediation guidance?
Every vulnerability finding includes a 'Copy Fix' button for immediate commands and an 'AI Fix Prompt' that users can paste into large language models like ChatGPT or Claude. This provides instant, AI-powered remediation guidance and code suggestions to help resolve identified security issues efficiently.
Which platforms and frameworks are supported by the scanner?
AI QA Monkey scans any publicly accessible website. It offers specialized detection for WordPress, Shopify, React/Next.js, Angular, Vue.js, Laravel, Django, and Node.js applications. Dedicated scanners are available for specific platforms and security aspects like DNS/SPF/DMARC validation and API security.
How long does a typical scan take and how often should I scan?
A typical security scan with AI QA Monkey completes in under 60 seconds. It is recommended to scan your website after every deployment, at least weekly for production sites, and immediately following any infrastructure changes to maintain a consistent security posture.