Ecommerce Malicious Script Scanner
Check your store for skimmer-like scripts, blacklist hits, outdated platform versions, mixed content, and certificate problems.
This scans a public storefront with a headless browser on our server. Use it only on a site you own or are authorized to audit. Reports stay in this session and are not published.
How to use this tool
- Enter your store URL and confirm you are allowed to scan it.
- Wait while the scanner loads public pages in a headless browser.
- Read the plain-language summary, open a finding for next steps, and download a PDF if you want a copy.
What the scan looks for
Card-skimming scripts are often a small extra tag on checkout. The scanner lists third-party scripts, flags hosts on a small known-skimmer list, and warns on obfuscated inline scripts, typosquat CDN names, mixed content, and certificates that are expired or close to expiry. When a WordPress, WooCommerce, Magento, or Shopify signature is visible, it is compared with a short list of minimum versions.
Critical labels are reserved for blacklist matches and known-bad script hosts. Other signals stay as warnings so a legitimate tag is less likely to be called an active compromise.
Why use FreeTools?
This tool sends the store URL to our server, which loads public pages the way a visitor's browser would. It does not log into your admin, place orders, or publish the report. Threat checks use Google Safe Browsing and VirusTotal when those API keys are configured. A missing finding is not proof that the store is secure.
FAQ
Who is this scanner for?+
Store owners and people they authorize. You must confirm ownership before a scan starts. It is not a tool for probing sites you do not control.
Are scan results public?+
No. The report is tied to a private job id in your browser session and expires in about 45 minutes. We do not publish results for other people's domains.
Does a clean report mean the store is safe?+
No. This is a best-effort public crawl of the homepage and, when we can find them, a product, cart, and checkout URL. It is not a penetration test.
Why might checkout be skipped?+
Some stores hide checkout behind a cart item, a login, or robots.txt. Those pages are reported as not scanned instead of being forced.
Related tools
Keep editing without leaving your browser.