Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
24i.dk offers a free web security scan for checking common Web security configuration issues on a website URL. The page highlights coverage of missing HTTPS, exposed server headers, insecure cookies, outdated JavaScript libraries, and missing Content Security Policy. It is better understood as a lightweight security baseline checker rather than a full vulnerability scanner or an enterprise-grade attack surface management platform.
In terms of protection scope, 24i.dk focuses on the basic security posture of public web pages. The HTTPS check can identify risks from unencrypted transmission; header detection looks at information such as Server, X-Powered-By, and X-AspNet-Version that may reveal the technology stack; cookie checks focus on Secure and HttpOnly, while also recommending SameSite; front-end dependency scanning can identify whether libraries such as jQuery, Angular, React, Vue, and Lodash are outdated; and the CSP check helps reduce XSS and code injection risks. Based on the page content, deployment appears to be online URL scanning, with no mention of local deployment, agents, or an account system. For management and alerting, the tool provides warnings and remediation suggestions, but does not disclose continuous monitoring, bulk asset management, reports, email alerts, or ticketing integrations.
The pricing information is very clear: the page repeatedly emphasizes free security scanning. However, there is no visible information about paid plans, an enterprise edition, API access, SLA, or service support pricing. Compliance certifications are also not disclosed, such as ISO, SOC 2, or GDPR data processing details, so it is not suitable as the sole security tool basis for organizations with strict procurement and audit requirements.
Its advantages are a low barrier to use, checks that align with common real-world website issues, and plain-language explanations of risks and remediation directions. This makes it suitable for webmasters and developers who want to perform a quick self-check. Its limitations are also clear: there is no visible support for authenticated scanning, exploit validation, logged-in session scanning, API security, WAF integration, CI/CD integration, SIEM integration, or long-term trend management. For larger organizations, it is better suited as a supplementary check rather than a primary security platform.
It is suitable for individual webmasters, SME corporate websites, and development teams performing basic security checks before launch. It can also be useful for security awareness training. The page does not provide information about access from mainland China, and payment methods are not disclosed; since the tool is free, procurement friction should be relatively low. If Chinese-language support, continuous monitoring, or enterprise-grade reporting is required, domestic cloud vendor security scanning products, Chaitin, KnownSec, and similar options may be worth considering. If you only need comparable international free checks, you can compare it with SecurityHeaders.com, Mozilla Observatory, and SSL Labs.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on 24i.dk official site.
24i.dk is an Denmark Security provider. TG4G tracks its product information, an overall rating of 5.0/10, and a China-accessibility score of Workable. Click "Visit Official Site" to reach 24i.dk directly.