FreeTools
Files processed locally in your browser

Ecommerce Malicious Script Scanner

Check your store for skimmer-like scripts, blacklist hits, outdated platform versions, mixed content, and certificate problems.

This scans a public storefront with a headless browser on our server. Use it only on a site you own or are authorized to audit. Reports stay in this session and are not published.

How to use this tool

  1. Enter your store URL and confirm you are allowed to scan it.
  2. Wait while the scanner loads public pages in a headless browser.
  3. Read the plain-language summary, open a finding for next steps, and download a PDF if you want a copy.

What the scan looks for

Card-skimming scripts are often a small extra tag on checkout. The scanner lists third-party scripts, flags hosts on a small known-skimmer list, and warns on obfuscated inline scripts, typosquat CDN names, mixed content, and certificates that are expired or close to expiry. When a WordPress, WooCommerce, Magento, or Shopify signature is visible, it is compared with a short list of minimum versions.

Critical labels are reserved for blacklist matches and known-bad script hosts. Other signals stay as warnings so a legitimate tag is less likely to be called an active compromise.

Why use FreeTools?

This tool sends the store URL to our server, which loads public pages the way a visitor's browser would. It does not log into your admin, place orders, or publish the report. Threat checks use Google Safe Browsing and VirusTotal when those API keys are configured. A missing finding is not proof that the store is secure.

FAQ

Who is this scanner for?+

Store owners and people they authorize. You must confirm ownership before a scan starts. It is not a tool for probing sites you do not control.

Are scan results public?+

No. The report is tied to a private job id in your browser session and expires in about 45 minutes. We do not publish results for other people's domains.

Does a clean report mean the store is safe?+

No. This is a best-effort public crawl of the homepage and, when we can find them, a product, cart, and checkout URL. It is not a penetration test.

Why might checkout be skipped?+

Some stores hide checkout behind a cart item, a login, or robots.txt. Those pages are reported as not scanned instead of being forced.

Related tools

Keep editing without leaving your browser.