ImmuniWeb is launching a free website security test tool that organizations can use to check whether their programs have vulnerabilities and whether they meet PCI DSS requirements.
Organizations can use the tool to perform security and compliance testing of external web applications.
Once the test starts , it checks for PCI DSS 6.2, 6.5 and 6.6 requirements, scans the website for vulnerabilities and checks version fingerprints of over 100 frameworks and over 165,000 of their plugins.
The tool checks over 20 HTTP headers related to security, encryption, or privacy against security best practices.

It checks for all known vulnerabilities and Assesses Content Security Policy to prevent XSS, CSRF, ransomware, and Cryptojacking attacks.
So far, among the nearly 40 million public websites audited, only 9.74% contain updated software, 2.07% meet the aforementioned PCI DSS requirements, and just 2.39% are protected with a WAF (Web Application Firewall).
Also, you can check the security of your iOS and Android application simply by downloading the app or entering its name from Google Play.
It is worth noting that phishing is one of the biggest modern threats as attackers follow a series of innovative social engineering methods to steal the victim's login credentials. The main vulnerability that hackers in a phishing attack is human error, so we must always be careful in any online action we take.
