IINSACHECK

INSA SECURITY CHECKLIST · REVIEW TOOLKIT

LESS NOISE.
MORE SIGNAL.

Run an authorized website check, scan project source locally, or bring both reports together. INSA Check maps results to the 102-item security checklist, with evidence and a clear view of what still needs human attention.

INSA CHECK / 0.2BUILT FOR CLARITY2026
102INSA checklist items
03automated + human review tiers
LOCALsource code stays on your machine
OPENevidence behind each result

01 / THE PRODUCT

Know what passed.
Know what needs a person.

INSA Check evaluates the 102 items in INSA’s website security checklist and preserves its sections, item numbers, and test titles. Each row shows Pass, Fail, Not applicable, Manual review, or Error, plus how it was evaluated and the evidence behind the result.

01

Website audit

Tier 1 makes passive checks against a website you’re authorized to assess. Run the dashboard on your own computer so requests come from your machine.

TIER 1 · URL SCAN
02

Source-code scan

Tier 2 statically analyzes supported project code on your machine. Python, JavaScript/TypeScript, PHP, Java, C#, Ruby, and Go are supported.

TIER 2 · LOCAL CLI
03

Manual review status

Reports keep undecided items marked Manual review and show what still needs a person. The dashboard’s interactive verdict, notes, and evidence view is not built yet; verdict recording is currently available through the core API.

TIER 3 · PARTIAL · DASHBOARD UI IN PROGRESS
SOURCE LANGUAGES

Python · JavaScript / TypeScript · PHP · Java · C# · Ruby · Go

Framework-aware checks are available for supported stacks. The CLI reads and parses files locally; it does not upload source code or run project code.

02 / A CLEAR WORKFLOW

From first scan
to useful next steps.

01

Run checks locally

Launch the dashboard or CLI on your computer. Confirm authorization before every website scan; URL checks are passive and do not submit forms or run exploit tests.

02

Review all 102 items

See each status, reason, and evidence. The readiness summary counts items still marked Manual review. Interactive verdict entry in the dashboard is not yet available.

03

Bring reports together

Import code results, merge them with website results, compare reports, then export JSON or a printable PDF. Manual verdicts can currently be recorded programmatically through the core API.

A useful signal, not a certificate. A Pass means the automated test found no problem. It does not certify a site. Many checklist items need authenticated, active, or human testing, and the tool does not replace a professional security review.

03 / DOCUMENTATION

Everything runs
where you run it.

This page is informational; it does not run scans. For the quick-start workflow, the dashboard and CLI run on your computer. No source code is uploaded. The landing page does not receive scan targets, code, or reports.

QUICK START / NODE.JS 20+

Install INSA Check.

Install the CLI with npm. To check a local project, use the code command below with your project directory. Files are analyzed locally and are never uploaded.

npm i insa-check
Full setup and usage guide
TERMINAL / LOCAL01 — 03

$ npx insa-check dashboard

# opens the local audit dashboard

$ npx insa-check code . --json code.json

# scans this project folder locally

$ npx insa-check --help

# see all scan options

SOURCE CODE NEVER LEAVES YOUR MACHINE

01 / WEBSITE

Scan an authorized URL

npx insa-check https://your-site.example --i-have-permission

Permission is required. The CLI refuses to scan without the confirmation flag. URL checks make passive requests, including a few well-known paths and protocol checks; they do not fuzz, brute-force, submit forms, or send injection payloads.

02 / CODE

Scan a local project

npx insa-check code <path>

Replace <path> with your project directory, or use . for the current folder. Source files are read and parsed locally; they are never executed or uploaded.

Which INSA checklist does it follow?

It follows “Minimum security testing of the website,” the 102-item checklist in Annex B of INSA’s Secure Website Management Standard, Version 1.0 (2014 EC). Reports retain the checklist’s sections and item numbers. Many items require human, authenticated, or active testing, so a Pass summary should never be treated as certification. INSA Check is an independent tool and is not affiliated with or endorsed by INSA.

Read the full guide ↗

LESS NOISE. MORE SIGNAL.

Make the next review
easier to understand.

Get started locally