// WEBSITE SECURITY
See your site the way an attacker does
A free website security check that runs forty passive tests across TLS, security headers, email spoofing, privacy and exposure — then hands you a grade out of 100 and a prioritised list of what to fix. About fifteen seconds. No signup, nothing installed.
// WHAT WE CHECK
Forty checks, five categories
Every check is scored, and every point you lose is shown against the finding that caused it — so the fastest way up is simply to fix the biggest number first.
TLS and certificates
HTTPS reachable, insecure address redirecting, certificate trusted and covering your hostname, days to expiry, deprecated TLS 1.0/1.1 still accepted, HSTS and preload readiness, IPv6. An expired certificate takes a site down behind a full-page browser warning.
Security headers
Content Security Policy and whether it is strong enough to matter, clickjacking protection, MIME-sniffing, referrer leakage, device permissions, and whether your server advertises its exact version to anyone who asks.
Domain spoofing
SPF and DMARC, and whether they actually enforce rather than merely monitor, plus MX, CAA and DNSSEC. Without an enforcing DMARC policy anyone can send mail that appears to come from you — how most invoice fraud starts.
Cookies and consent
Whether non-essential cookies are set before consent, whether a consent mechanism exists at all, an inventory of third-party trackers, cookie security attributes, and a reachable privacy policy. Pre-consent cookies are the most common EU regulator finding against small sites.
What your site reveals
Mixed content, published CMS version, WordPress readme.html, plugin and theme versions leaking through asset URLs, directory listings, a robots.txt that maps your admin paths, and whether a security.txt exists.
Infrastructure standing
Whether your server address appears on spam and malware blocklists, whether a WAF or CDN sits in front of you, HTTP/3 support, and how long the domain has been registered. A listed IP quietly sends your email to junk.
// HOW IT WORKS
Three steps, no account
// PRICING
Free report, or the full one
- Overall grade out of 100
- Score for each of the five categories
- Certificate, server and platform overview
- Issue counts by severity
- Every passing check, listed
- Full detail on a selection of findings
- Every remaining finding, in priority order
- The exact evidence behind each result
- Step-by-step fixes with config you can paste
- PDF, CSV and JSON export — send it to a developer or client
- Re-scans for twelve months to confirm fixes worked
- Delivered immediately as a private link
Payment is handled by Stripe, which acts as merchant of record and issues the tax receipt. Purchase terms, including the digital-delivery and cancellation position, are in our Terms of Service.
// HOW THE SCAN BEHAVES
Passive by design
We request only what your site already serves publicly — your homepage, robots.txt, security.txt and a few conventional paths — along with public DNS and registry records. Our scanner identifies itself honestly in its User-Agent. Nothing intrusive is attempted, no vulnerability is exploited, no login is required.
Two checks need proof you own the domain
Whether a .git directory or a .env file is publicly readable are among the most damaging things we can find: the first usually exposes your entire source code, the second typically hands over database credentials and payment keys in one request.
Both also mean requesting a path your site does not intend to publish, so we will not point them at a domain nobody has proven they control. Run a scan and you will be offered a one-line DNS TXT record; publish it, press check, and those two run automatically. That line is what separates a website checker from scanning a stranger’s server uninvited.
How we score
Each check carries a weight inside its category. A pass earns full weight, a partial result half, a failure none. Checks we could not complete are excluded from the score rather than counted against you — a site should never be marked down because our scanner could not reach something. Grades: A 90+, B 80, C 65, D 50, E 35, F below.
A good grade is not a clean bill of health. This looks at configuration visible from outside your website. It cannot see your source code, your plugins’ internals, your passwords or your backups, and it is not a penetration test, a compliance certification, or professional security advice.
Check your site now
Fifteen seconds, no signup, and you will know exactly where you stand. Most sites we scan lose their first ten points to two missing headers.
Run the free check →