SurfaceScan™
Audit any website’s privacy exposure for free — JavaScript, cookies, third-party resources, fingerprinting signals, tracking services, and security headers — scored out of 100.
Static analysis · No JavaScript · Pure PHP + cURL
Scan a website
Fetches the target URL server-side via cURL, reads HTTP response headers, and analyses the static HTML for scripts, cookies, third-party resources, fingerprinting APIs, and known trackers. Results reflect static content only — JS-rendered SPAs may score higher than their true exposure.
kagi.com
Mixed — noticeable client-side footprint and some exposure.
Scan quality: full page retrieved — results are reliableCategory breakdown
5 external scripts
No cookies set
2 third-party domains: cloudflare.com, googleapis.com
No fingerprinting signals detected
No tracking or analytics detected
Present: HSTS, X-Frame-Options. Missing: Content-Security-Policy, Referrer-Policy, X-Content-Type-Options, Permissions-Policy