Skip to main content
The Scanner gives you on-demand security testing for the two surfaces attackers probe most: your public websites and your mobile applications. Each scanner runs against assets you’ve already registered (or uploaded) and reports the vulnerabilities, severities, and fixes that matter.
Path: Scanner

Web Scanner

Scan your registered domains for web vulnerabilities and track a security score over time.

App Scanner

Upload an Android or iOS app package to analyze it for vulnerabilities, privacy risks, and hardcoded secrets.

Which scanner do I use?

  • Web Scanner — for the websites and subdomains you manage in Osto. It scans live domains and surfaces vulnerabilities, top attack paths, and a security score.
  • App Scanner — for mobile app builds. Upload an .apk (Android) or .ipa (iOS) file and Osto analyzes the binary for security and privacy issues.
Both scanners are read-only assessments. Running a web scan doesn’t change your site, and uploading an app build doesn’t publish or modify it anywhere.