Website audit
Tier 1 makes passive checks against a website you’re authorized to assess. Run the dashboard on your own computer so requests come from your machine.
TIER 1 · URL SCANINSA SECURITY CHECKLIST · REVIEW TOOLKIT
Run an authorized website check, scan project source locally, or bring both reports together. INSA Check maps results to the 102-item security checklist, with evidence and a clear view of what still needs human attention.
01 / THE PRODUCT
INSA Check evaluates the 102 items in INSA’s website security checklist and preserves its sections, item numbers, and test titles. Each row shows Pass, Fail, Not applicable, Manual review, or Error, plus how it was evaluated and the evidence behind the result.
Tier 1 makes passive checks against a website you’re authorized to assess. Run the dashboard on your own computer so requests come from your machine.
TIER 1 · URL SCANTier 2 statically analyzes supported project code on your machine. Python, JavaScript/TypeScript, PHP, Java, C#, Ruby, and Go are supported.
TIER 2 · LOCAL CLIReports keep undecided items marked Manual review and show what still needs a person. The dashboard’s interactive verdict, notes, and evidence view is not built yet; verdict recording is currently available through the core API.
TIER 3 · PARTIAL · DASHBOARD UI IN PROGRESSPython · JavaScript / TypeScript · PHP · Java · C# · Ruby · Go
Framework-aware checks are available for supported stacks. The CLI reads and parses files locally; it does not upload source code or run project code.02 / A CLEAR WORKFLOW
Launch the dashboard or CLI on your computer. Confirm authorization before every website scan; URL checks are passive and do not submit forms or run exploit tests.
See each status, reason, and evidence. The readiness summary counts items still marked Manual review. Interactive verdict entry in the dashboard is not yet available.
Import code results, merge them with website results, compare reports, then export JSON or a printable PDF. Manual verdicts can currently be recorded programmatically through the core API.
A useful signal, not a certificate. A Pass means the automated test found no problem. It does not certify a site. Many checklist items need authenticated, active, or human testing, and the tool does not replace a professional security review.
03 / DOCUMENTATION
This page is informational; it does not run scans. For the quick-start workflow, the dashboard and CLI run on your computer. No source code is uploaded. The landing page does not receive scan targets, code, or reports.
Install the CLI with npm. To check a local project, use the code command below with your project directory. Files are analyzed locally and are never uploaded.
npm i insa-checknpx insa-check code ./my-project$ npx insa-check dashboard
# opens the local audit dashboard
$ npx insa-check code . --json code.json
# scans this project folder locally
$ npx insa-check --help
# see all scan options
SOURCE CODE NEVER LEAVES YOUR MACHINE
npx insa-check https://your-site.example --i-have-permissionPermission is required. The CLI refuses to scan without the confirmation flag. URL checks make passive requests, including a few well-known paths and protocol checks; they do not fuzz, brute-force, submit forms, or send injection payloads.
npx insa-check code <path>Replace <path> with your project directory, or use . for the current folder. Source files are read and parsed locally; they are never executed or uploaded.
It follows “Minimum security testing of the website,” the 102-item checklist in Annex B of INSA’s Secure Website Management Standard, Version 1.0 (2014 EC). Reports retain the checklist’s sections and item numbers. Many items require human, authenticated, or active testing, so a Pass summary should never be treated as certification. INSA Check is an independent tool and is not affiliated with or endorsed by INSA.
Read the full guide ↗LESS NOISE. MORE SIGNAL.