Web Recon

App Store App Utilities TRY 249.99
3 Oct 2026launched yesterday
–No ratings yetRead reviews
n/aApple doesn’t publish installs
WorldwideSold in 50+ App Store storefronts
1.0latest version · today

Screenshots

About

One letter. And exactly what to change. Web Recon grades a website's security posture end to end and tells you, in order, what to fix. You get a grade, the reason behind it, and the single change that raises it most. WHAT IT CHECKS • Transport — HTTPS enforcement, TLS version, legacy protocol support, certificate validity and expiry, key strength, OCSP stapling, the full HSTS policy including preload eligibility, and whether the page pulls anything over plaintext. • Headers — Content-Security-Policy and whether it actually constrains anything, including whether its allowlist can be walked straight through; Subresource Integrity on third-party scripts; MIME sniffing, framing, Referrer-Policy, Permissions-Policy and cross-origin isolation. • Cookies — Secure, HttpOnly and SameSite judged per cookie, plus __Host- and __Secure- prefixes and over-broad Domain scope. • Redirect chain — length, plaintext hops, cross-origin handoffs and open-redirect patterns. • Information exposure — version banners, X-Powered-By, debug headers and directory listings. • Ownership — registration expiry, registrar and ASN, CAA records, DNSSEC. IT ASKS WHETHER YOUR CSP ACTUALLY WORKS Plenty of tools will tell you whether a Content-Security-Policy exists. Web Recon asks whether it works. A policy that allowlists a shared bucket domain, or a CDN serving arbitrary packages, hands script execution to anyone who asks: it looks strict and stops nothing. The same goes for a script loaded from someone else's server with no integrity hash. polyfill.io was a script on six figures' worth of sites when the domain changed hands, and the new owner served malware to all of them. THE FIX LIST IS THE PRODUCT Every failing check tells you why it matters, what was observed, and the exact configuration to set, ready to copy. The list is ranked by how much each change raises the grade, so you can start at the top and stop when you like. SEE WHETHER YOUR FIX WORKED Re-run and compare. Web Recon shows the delta, the grade change, and the part nobody thinks to check: anything that was passing before and isn't now. HONEST ABOUT WHAT IT DOESN'T KNOW When a registry rate-limits us, a resolver strips the records we need, or a page runs too long to read to the end, that check is reported as not evaluated and left out of the score. It is never counted against your site, and never counted in your favor either. A partial grade says so on its face. ON IPHONE AND IPAD The grade leads and the evidence is one tap away. iPad runs three panes side by side in landscape. With Wi-Fi and cellular both up, Web Recon inspects the certificate over each path and tells you when they disagree, which is how you catch something terminating TLS on one of them. BUILT FOR ONE JOB One site at a time, on your say-so. Web Recon fetches your site's front page and follows its redirects. It does not crawl, enumerate paths, guess filenames or probe for vulnerabilities. There is no account, no telemetry and no analytics, and nothing is uploaded. Your history stays on your device. Export any report as Markdown, JSON or PDF. Part of the 404 Tools Recon line. Hands off to, and takes handoffs from, HTTP Recon, Cert Recon, WHOIS Recon and DNS Recon.Read more
One letter. And exactly what to change. Web Recon grades a website's security posture end to end and tells you, in order, what to fix. You get a grade, the reason behind it, and the single change that raises it most. WHAT IT CHECKS • Transport — HTTPS enforcement, TLS version, legacy protocol support, certificate validity and expiry, key strength, OCSP stapling, the full HSTS policy including preload eligibility, and whether the page pulls anything over plaintext. • Headers — Content-Security-Policy and whether it actually constrains anything, including whether its allowlist can be walked straight through; Subresource Integrity on third-party scripts; MIME sniffing, framing, Referrer-Policy, Permissions-Policy and cross-origin isolation. • Cookies — Secure, HttpOnly and SameSite judged per cookie, plus __Host- and __Secure- prefixes and over-broad Domain scope. • Redirect chain — length, plaintext hops, cross-origin handoffs and open-redirect patterns. • Information exposure — version banners, X-Powered-By, debug headers and directory listings. • Ownership — registration expiry, registrar and ASN, CAA records, DNSSEC. IT ASKS WHETHER YOUR CSP ACTUALLY WORKS Plenty of tools will tell you whether a Content-Security-Policy exists. Web Recon asks whether it works. A policy that allowlists a shared bucket domain, or a CDN serving arbitrary packages, hands script execution to anyone who asks: it looks strict and stops nothing. The same goes for a script loaded from someone else's server with no integrity hash. polyfill.io was a script on six figures' worth of sites when the domain changed hands, and the new owner served malware to all of them. THE FIX LIST IS THE PRODUCT Every failing check tells you why it matters, what was observed, and the exact configuration to set, ready to copy. The list is ranked by how much each change raises the grade, so you can start at the top and stop when you like. SEE WHETHER YOUR FIX WORKED Re-run and compare. Web Recon shows the delta, the grade change, and the part nobody thinks to check: anything that was passing before and isn't now. HONEST ABOUT WHAT IT DOESN'T KNOW When a registry rate-limits us, a resolver strips the records we need, or a page runs too long to read to the end, that check is reported as not evaluated and left out of the score. It is never counted against your site, and never counted in your favor either. A partial grade says so on its face. ON IPHONE AND IPAD The grade leads and the evidence is one tap away. iPad runs three panes side by side in landscape. With Wi-Fi and cellular both up, Web Recon inspects the certificate over each path and tells you when they disagree, which is how you catch something terminating TLS on one of them. BUILT FOR ONE JOB One site at a time, on your say-so. Web Recon fetches your site's front page and follows its redirects. It does not crawl, enumerate paths, guess filenames or probe for vulnerabilities. There is no account, no telemetry and no analytics, and nothing is uploaded. Your history stays on your device. Export any report as Markdown, JSON or PDF. Part of the 404 Tools Recon line. Hands off to, and takes handoffs from, HTTP Recon, Cert Recon, WHOIS Recon and DNS Recon.

Store page changes

Title, subtitle, icon, screenshots and price

No changes recorded yet. Each time we check this app we compare its store page with the last one and log what changed. Create a free account and save this app to have its store page checked every day.

Versions

  1. Version 1.0First seen · 4 Oct 2026

Countries

Worldwide

Apple lists this app in 50 or more storefronts, so it is available almost everywhere.

Turkey

Chart positions

Not seen in the charts we track yet.

Similar apps