Skip to main content

Free surface scan

Check any site for visible license signals

A 20-second look at one public URL. It won't inventory what you ship, but it will show you where the obvious gaps are.

sourcetrust.dev/checkSurface only
CAPTCHA verification

No sign-up. One scan every 30 seconds.

What it can see

  • Whether a license or attribution page exists
  • Third-party scripts, bundles, and embedded services
  • CMS and framework fingerprints in headers and markup
  • Web fonts, icon sets, and obvious asset sources

What it can't

  • See inside your build or dependencies
  • Confirm the actual license of anything
  • Replace a reviewed, published record
Full limits

This scan does not reach your repos, mobile builds, or release binaries. It flags visible signals only, and the component list will usually be incomplete. Many dependencies simply will not appear here.

When you use SourceTrust, you connect what you actually ship and scan the full inventory from lockfiles, SBOMs, and repositories. That is the list you can review, publish, and defend. Log in to SourceTrust.

What this scan can and cannot see

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.