Docker Security Scanner
A new tool extracted from the codebase.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Check a container configuration for risky settings
A container is only as secure as how it is run, and the defaults are not always the safe choice. This tool reviews Docker configuration for the settings that commonly weaken container security, so you can harden your own containers before they reach production.
The settings that matter most
The high-impact issues are well known: running as root inside the container, which turns a container escape into host access; mounting the Docker socket, which effectively grants control of the host; running privileged, which removes most isolation; and exposing more than the container needs. Each trades away a layer of the isolation that makes containers safe. Reviewing for them is how you keep that isolation intact.
Defensive review of your own images
This is about hardening containers you build and run, which is ordinary operational security. Finding a risky setting in review is far cheaper than discovering it after an incident. The analysis runs entirely in your browser, so your configuration is never uploaded, which matters when it describes your own infrastructure.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
- CI/CD Risk Analyzer — Analyze CI/CD pipelines for security risks and misconfigurations.
Frequently Asked Questions
Why is running as root in a container risky?
Because if an attacker escapes the container, root inside can become root on the host. Running as a non-root user keeps a container escape contained.
Why does mounting the Docker socket matter?
Because access to the Docker socket effectively grants control of the host’s Docker daemon, which can be used to take over the host. It should rarely be mounted into a container.
What does privileged mode do?
It removes most of the isolation between the container and the host, granting broad access. It should be avoided unless genuinely required and understood.
Is this scanning my running containers?
No. It reviews container configuration you provide, helping you harden your own images and settings before deployment.
Is my configuration uploaded?
No. The review runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
CI/CD Security Gap Analyzer
DevOpsChecklist based analyzer for CI/CD pipeline security gaps.
Terraform Scanner
DevOpsA new tool extracted from the codebase.
SQL Formatter
DevOpsFormat and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.