GuardPad - Security Scanner

Security Grade · OWASP · Email

Free · In‑App Purchases · Designed for iPad. Not verified for macOS.

v1.3: DNS-only fallback — scan domains even when servers are unreachable. Context-aware grading, email security, OWASP compliance, and Reporting API detection. Scan any URL and get an instant A+ to F security grade with actionable fixes for your web server. GuardPad analyzes 11 HTTP security headers, SSL/TLS certificates, cookies, email security (SPF/DMARC/DKIM), DNSSEC, CAA records, and redirect chains — then adapts your grade to your site type. A blog isn't held to the same standard as a banking app. NEW: DNS-only fallback — when a web server is unreachable, GuardPad automatically analyzes DNS records and delivers a partial security grade. Mail-only domains, temporarily down sites, and non-HTTP services all get useful results instead of a dead-end error. Context-sensitive grading, email authentication analysis, OWASP Top 10:2025 compliance mapping, Trusted Types CSP detection, cookie analysis, CSP depth scoring, cross-origin isolation grading, and smart recommendations ordered by relevance to your site type. Try every feature free for 3 days. No account required. No data collected. FREE FEATURES: • DNS-only fallback — get security grades even when web servers are unreachable • Context-sensitive grading — grades tuned to 5 site types (static, SPA, API, CMS, generic) • Grade explanations — see exactly why your site type got that score • Analyze 11 security headers (HSTS, CSP, COOP, COEP, CORP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection, Server) • Email security analysis — SPF, DMARC, and DKIM graded with detailed findings • Cookie security analysis (Secure, HttpOnly, SameSite, __Host- prefix) • MX record quality analysis with null MX and bare IP detection • CSP depth analysis (nonce, strict-dynamic, Trusted Types detection, Report-Only flagging) • SSL/TLS certificate inspection with cipher suite details • Redirect chain visualization with quality grading • OWASP Top 10:2025 compliance mapping • Report-To and NEL (Network Error Logging) detection • Deprecated header detection (HPKP, Expect-CT, Feature-Policy) • security.txt (RFC 9116) detection • Quick Fix mode — see your highest-impact issues first • Instant A+ to F grade with weighted score breakdown • Actionable WHAT/WHY/FIX diagnostics for every finding • Domain-grouped scan history with trend tracking • Re-scan diff — see exactly what changed since your last scan • Works offline for reviewing past results PRO FEATURES (one-time purchase): • Batch scanning — scan up to 50 URLs at once with aggregate report • Shareable security grade badge (SVG/PNG) for READMEs and dashboards • Shareable grade card — amber-themed share image • iPad side-by-side scan comparison with improvement tracking • Server-specific fix code snippets for nginx, Apache, Express.js, and Caddy • Smart recommendations — fix suggestions ordered by relevance to your site type • CORS configuration tester — verify cross-origin resource sharing settings • DNS record lookup with DNSSEC validation status and CAA record grading • Export results as PDF or Markdown • Full certificate chain inspection Built for developers who ship secure web applications. Whether you maintain nginx, Apache, Express.js, or Caddy servers, GuardPad gives you the tools to verify your security configuration meets industry standards. No account required. No data collected. All analysis happens on your device.

  • This app hasn’t received enough ratings or reviews to display an overview.

NEW: DNS-only fallback — when a web server is unreachable, GuardPad automatically runs DNS analysis and delivers a partial security grade. Works for mail-only domains, temporarily down sites, and non-HTTP services. NEW: DNS-only results show a distinct dashed-ring grade, "DNS ONLY" badge, email-focused report card, and adapted methodology breakdown (70% email / 10% DNSSEC / 10% CAA / 10% MX). NEW: MX record quality analysis — detects multiple mail servers, null MX (RFC 7505), bare IP addresses, and priority ordering. NEW: DNS-only integration across the app — history badges, batch auto-fallback with aggregate stats, cross-mode diff, share card, PDF/Markdown exports, and VoiceOver announcements. NEW: Context-sensitive grading — your grade now accounts for site type. A static blog isn't held to the same standard as a banking SPA. Five site types detected automatically: static, SPA, API, CMS, and generic. NEW: Grade explanations — tap any grade to see exactly which headers matter most for your site type and how weights were adjusted. NEW: Site type override — disagree with the detection? Override it and watch your grade recalculate live. NEW: Smart recommendations — fix suggestions ordered by relevance to your site type. NEW: Reporting API detection — Report-To and Network Error Logging (NEL) headers identified. NEW: Email security analysis — SPF, DMARC, and DKIM records graded individually. NEW: OWASP Top 10:2025 compliance mapping — each finding mapped to the risk it mitigates. NEW: DNSSEC validation and CAA record grading in DNS tools. NEW: Trusted Types CSP detection with A+ grade boost. IMPROVED: Re-scan diff overlay with inline grade change badges. IMPROVED: Shareable amber-themed grade card image. IMPROVED: 3-tab layout (Scan / History / Tools) with iPad sidebar. IMPROVED: Batch scan rows show site type badges. IMPROVED: PDF and Markdown exports include all analysis sections.

The developer, Olof Petterson, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .

  • Data Not Collected

    The developer does not collect any data from this app.

    Privacy practices may vary, for example, based on the features you use or your age. Learn More

    The developer has not yet indicated which accessibility features this app supports. Learn More

    Seller
    • Olof Petterson
    Size
    • 6.5 MB
    Category
    • Developer Tools
    Compatibility
    Requires iOS 26.2 or later.
    • iPhone
      Requires iOS 26.2 or later.
    • iPad
      Requires iPadOS 26.2 or later.
    • Mac
      Requires macOS 26.2 or later and a Mac with Apple M1 chip or later.
    • Apple Vision
      Requires visionOS 26.2 or later.
    Languages
    • English
    Age Rating
    4+
    In-App Purchases
    Yes
    Copyright
    • © 2026 Olof Petterson. All rights reserved.