Scan Your Website Security
Discover common security misconfigurations and publicly exposed resources — missing headers, weak SSL, exposed backups, and more — in under a minute.
What We Check
10 passive, non-destructive check categories run against every scan.
HTTPS & Redirects
Confirms HTTPS is available and plain HTTP properly redirects.
Security Headers
CSP, HSTS, X-Frame-Options, and more, with pass/warn/missing status.
SSL/TLS Configuration
Certificate validity, expiration, and hostname matching.
Cookie Security
Secure, HttpOnly, and SameSite flags on every cookie.
CORS Configuration
Flags overly permissive cross-origin resource sharing.
Exposed Files
Checks for publicly accessible .env, backups, and config files.
Directory Listing
Detects browsable directory indexes on common paths.
JavaScript Exposure
Source maps, debug code, and leaked-secret patterns (redacted).
Technology Detection
Passively identifies your stack — server, CMS, frameworks.
Risk Scoring
A single 0–100 score with severity-weighted findings.
How It Works
Enter a URL
Paste the site you want to check — no signup required for a preview.
We scan passively
Read-only HTTP requests only. Nothing is modified, deleted, or exploited.
Get a scored report
A 0–100 security score with clear, prioritized recommendations.