Hack My Website

Automated web-application security scanner that runs 200+ checks across DAST (OWASP ZAP), CVE exploit templates (Nuclei), static analysis (Semgrep/SAST), and SaaS-misconfiguration checks, producing a 0-100 AI Launch Score with go/no-go readiness bands and 1-click AI remediation fix prompts for Cursor, Claude Code, and Windsurf. Built by Aivi Labs for teams shipping sites made with AI coding tools (Lovable, Bolt, v0, Cursor, Claude Code); currently early-access/waitlist with no public developer API.

Hack My Website publishes 1 API on the APIs.io network. Tagged areas include Application Security, Web Security, Vulnerability Scanning, DAST, and SAST.

Hack My Website’s developer surface includes documentation, signup flow, support, pricing, and 6 more developer resources.

25.3/100 emerging Agent 0/100 human only Full breakdown ↓
scored 2026-09-18 · rubric v0.22.0
1 APIs
Application SecurityWeb SecurityVulnerability ScanningDASTSASTCybersecurityAppSecDevSecOpsAI RemediationSoftware-as-a-Service

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-18 · rubric v0.22.0
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero: never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and several others — scorable at all.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/hack-my-website: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Hack My Website

Automated website security scanner. Only an agent-native surface (llms.txt) is publicly declared; no conventional API contract (OpenAPI/GraphQL/AsyncAPI/gRPC/SOAP) is published....

Pricing Plans 1

Published pricing tiers and plan structures.

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Hack My Website Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Access & Security 1

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
name: Hack My Website
description: Automated web-application security scanner that runs 200+ checks across DAST (OWASP ZAP), CVE exploit templates
  (Nuclei), static analysis (Semgrep/SAST), and SaaS-misconfiguration checks, producing a 0-100 AI Launch Score with go/no-go
  readiness bands and 1-click AI remediation fix prompts for Cursor, Claude Code, and Windsurf. Built by Aivi Labs for teams
  shipping sites made with AI coding tools (Lovable, Bolt, v0, Cursor, Claude Code); currently early-access/waitlist with
  no public developer API.
url: https://raw.githubusercontent.com/api-evangelist/hack-my-website-automated-website-security-scanner/refs/heads/main/apis.yml
created: '2026-09-18'
modified: '2026-09-18'
specificationVersion: '0.21'
tags:
- Application Security
- Web Security
- Vulnerability Scanning
- DAST
- SAST
- Cybersecurity
- AppSec
- DevSecOps
- AI Remediation
- Software-as-a-Service
tags_raw:
- Application Security
- Web Security
- Vulnerability Scanning
- DAST
- SAST
- Cybersecurity
- AppSec
- DevSecOps
- AI Remediation
- SaaS
apis:
- name: Hack My Website
  description: Automated website security scanner. Only an agent-native surface (llms.txt) is publicly declared; no conventional
    API contract (OpenAPI/GraphQL/AsyncAPI/gRPC/SOAP) is published. The app's own backend (/api) is private, robots-disallowed,
    and serves no OpenAPI.
  humanURL: https://hackmywebsite.io
  baseURL: https://hackmywebsite.io
  tags:
  - Application Security
  - Web Security
  - Vulnerability Scanning
  - DAST
  - SAST
  - Cybersecurity
  - AppSec
  - DevSecOps
  - AI Remediation
  - Software-as-a-Service
  tags_raw:
  - Application Security
  - Web Security
  - Vulnerability Scanning
  - DAST
  - SAST
  - Cybersecurity
  - AppSec
  - DevSecOps
  - AI Remediation
  - SaaS
  properties:
  - type: LLMsTxt
    url: llms/hack-my-website-llms.txt
  - type: LLMsTxt
    url: https://hackmywebsite.io/llms.txt
  - type: Documentation
    url: https://hackmywebsite.io/how-it-works
  - type: Documentation
    url: https://hackmywebsite.io/methodology
common:
- type: Website
  url: https://hackmywebsite.io
- type: Documentation
  url: https://hackmywebsite.io/how-it-works
- type: SignUp
  url: https://hackmywebsite.io/signup
- type: Login
  url: https://hackmywebsite.io/login
- type: Support
  url: mailto:support@hackmywebsite.io
- type: PrivacyPolicy
  url: https://hackmywebsite.io/privacy-policy
- type: TermsOfService
  url: https://hackmywebsite.io/terms-and-conditions
- type: Pricing
  url: https://hackmywebsite.io
- type: Plans
  url: plans/hack-my-website-plans-pricing.yml
- type: DomainSecurity
  url: security/hack-my-website-domain-security.yml
maintainers:
- FN: Hack My Website
  email: support@hackmywebsite.io
  url: https://hackmywebsite.io/
generated:
  by: apis.io/add
  model: claude-opus-4-8
  confidence: 55
  at: '2026-09-18T15:55:22.076Z'
aid: hack-my-website
x-enrichment:
  date: '2026-09-18'
  status: minimal
  artifacts_added: 4
  pass: local-v3
x-coverage:
  state: none
  reason: no-developer-program
  detail: Hack My Website (by Aivi Labs) ships an end-user SaaS security scanner in early-access/waitlist; its only public
    API path (/api) is a private, robots-disallowed app backend that serves no OpenAPI, and no developer portal, SDK, webhooks
    or machine-readable contract is published anywhere.
  evidence:
  - url: https://hackmywebsite.io/api/openapi.json
    status: 404
  - url: https://hackmywebsite.io/openapi.json
    status: 404
  - url: https://hackmywebsite.io/robots.txt
    status: 200
  checked: '2026-09-18'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/hack-my-website"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/hack-my-website/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/hack-my-website/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.