XowiaScan
Pro feature

Automate XowiaScan with the API

Drive every server-side tool from your own scripts and pipelines with scoped API keys. Recon, scanning and lookups — fully programmable.

Scoped API keys

Restrict a key to specific tools; track usage; revoke anytime.

Bearer auth

Standard Authorization: Bearer — works with any HTTP client.

Same guardrails

Rate limits, scope rules and SSRF protection apply to API calls too.

What you can automate

21 server tools are API-callable

Vulnerability Scanner

All-in-one passive + opt-in active scanner — feed a URL or a raw HTTP request and surface misconfigurations and vulnerabilities, graded by severity.

Subdomain Discovery

Aggregate subdomains from crt.sh, OTX, Shodan, CertSpotter & more.

WHOIS Lookup

Query registrar WHOIS records over port 43.

Port Intelligence

Passive open-port & CVE exposure lookup (Shodan InternetDB) plus ready-to-run nmap/naabu/rustscan commands — no scan traffic leaves our servers.

CNAME / DNS Checker

Resolve A/AAAA/CNAME/MX/NS/TXT/CAA, follow the CNAME chain, flag subdomain-takeover candidates and check SPF/DMARC + wildcard DNS.

Wayback URL Extractor

Pull historical URLs from the Internet Archive, then mine parameters, subdomains and sensitive files for testing.

HTTP ProbeMaster

Bulk-probe hosts in parallel — status, redirects, title, tech stack, server, IP & timing — flags notable findings (dir listing, phpinfo, API docs) with filtering & export.

Image EXIF Extractor

Batch-extract EXIF + IPTC + XMP metadata (GPS, device serials, owner, software) from uploaded images or remote URLs — with a leak summary & reverse-geocoded GPS.

Security Header Analyzer

Fetch a URL and grade its security headers.

CORS Misconfig Tester

Probe CORS ACAO/ACAC behavior with a spoofed Origin.

DNS Recon Pro

AXFR test, SPF/DMARC/DKIM, DNSSEC & dangling-CNAME check.

Robots & Sitemap Harvester

Pull disallowed paths and sitemap URLs.

Tech Fingerprint

Detect server, CMS, frameworks & libraries.

security.txt Checker

Fetch & validate /.well-known/security.txt.

CSP / CORS Analyzer

Grade Content-Security-Policy & CORS exposure.

Redirect / SSRF Fuzzer

Test a parameter for open-redirect & SSRF reflection.

Subdomain Takeover Scanner

Fingerprint unclaimed CNAMEs (S3, GitHub, Heroku…).

CVE Lookup

Search CVEs by product/keyword (CIRCL feed).

Bugcrowd VRT

Browse the Vulnerability Rating Taxonomy with enrichment.

WebPad

Cloud scratchpad — saved to your account.

Tracking Lab (demo)

Educational request-inspection demo (lab use only).

Full endpoint reference, auth details and curl examples are available to Pro accounts.