Utility

Open Redirect Scanner

A new tool extracted from the codebase.

Last reviewed by the Radiatus Cloud team

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Check whether your redirects are safe

An open redirect is when your application redirects to a URL taken from user input without restriction, letting an attacker craft a link on your trusted domain that sends users to a malicious site. This checker helps you review redirects in your own application for that weakness.

Why open redirects are dangerous

Because the link appears to be on your trusted domain, users and filters trust it, but it forwards them elsewhere, which is used in phishing to lend credibility to a malicious destination. The weakness is subtle because the redirect works as intended for legitimate uses; the problem is accepting an unrestricted destination.

The defence

The defence is to never redirect to a raw user-supplied URL: use an allowlist of permitted destinations, or map an identifier to a known URL server-side. Reviewing your redirects confirms none accept an arbitrary external destination. This is for defensive assessment and education around systems you own or protect, or for authorised security testing and awareness, not for targeting others. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input concerns your own security posture.

Related tools

  • User Agent Parser — Parse a User-Agent string into browser, engine, operating system and device. Explains why UA strings are unreliable and what to use instead.
  • QR Code Generator — Generate QR codes for URLs, text, Wi-Fi and contact details. Adjustable error correction and size, produced entirely in your browser.
  • Credit Card Validator — Validate a card number with the Luhn algorithm and identify the issuing network from its prefix. Runs locally, nothing is transmitted.
  • Text Case Converter — Convert text between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, Title Case and sentence case. Runs entirely in your browser.

Frequently Asked Questions

What is an open redirect?

When your application redirects to a URL from user input without restriction, letting an attacker craft a trusted-looking link that forwards users elsewhere.

Why is it dangerous?

Because the link appears on your trusted domain, so users and filters trust it, which phishing exploits to lend credibility to a malicious destination.

How do I fix it?

Never redirect to a raw user-supplied URL. Use an allowlist of permitted destinations, or map an identifier to a known URL on the server.

Is this for my own site?

Yes. It is defensive review of redirects in an application you own, to close a weakness attackers use for phishing.

Is my input uploaded?

No. It runs entirely in your browser.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.