logo
Gixy-Next: NGINX Configuration Security Scanner
Online In-Browser Scanner
Initializing search
    MegaManSec/Gixy-Next
    MegaManSec/Gixy-Next
    • Gixy-Next Overview
    • Usage Guide
    • In-Browser Scanner
    • Live Config Dump: nginx -T
      • Duplicate Content-Type
      • Multiline Response Headers
      • Header Inheritance Issues
      • Alias Path Traversal
      • Allow Without Deny
      • Missing default_server Flag
      • error_log Set To Off
      • Map Default Value Missing
      • Host Header Spoofing
      • HTTP Response Splitting
      • If Is Evil (in Location)
      • Invalid Regex Captures
      • Low Keepalive Requests
      • Weak Referer/Origin Validation
      • proxy_pass Path Normalization
      • Regex Denial of Service
      • External DNS Resolvers
      • Return Bypasses Allow/Deny
      • Server Side Request Forgery
      • Outdated/stale cached DNS records used in proxy_pass
      • Uncached try_files
      • Unanchored Regex Pattern
      • Referer Check Bypass
      • NGINX Version Disclosure
      • Low worker_rlimit_nofile
    • Configuration Guide
    • Custom Variables & Drop-ins
    • Contributing to Gixy-Next

    In-Browser Scanner

    In-browser Scanner

    This page is the in-browser build of Gixy-Next. It runs entirely in your browser using WebAssembly, and your config is analyzed locally; nothing is uploaded to any server.

    Config Format Tip

    For the best results, scan the output of gixy -T since it expands all include directives into a single effective config. See Nginx -T Live Configuration Dumps for more details.