Website security check
The security basics anyone can see from outside: HTTPS, the certificate and when it expires, the security headers browsers use to protect your visitors, and whether your server tells attackers what version it runs.
About a minute. No signup for the summary.
What this check looks at
Plus the rest of the 30+ checks — every scan runs all of them.
Why it matters
Missing security headers do not break anything you can see — which is why most sites lack them. Each missing one comes with the exact line to add.
An expiring certificate takes a site down overnight. We show how many days are left.
What it does not do
It is not a penetration test: it does not try to break in, log in or scan ports. It checks what every visitor's browser receives.
Questions
Which security headers do you check?
Strict-Transport-Security (HSTS), Content-Security-Policy, X-Content-Type-Options and Referrer-Policy.
Is this a vulnerability scan?
No. It does not attack or probe your site. It reads what your server sends to every visitor and flags what is missing.
Do you give the fix?
Yes — for every missing header, the exact line to add.