all listings checked today 18:18 UTC 1146 live 1 in the graveyard how the check works →
TrueTier
Free · 30+ checks · about a minute

Website security check

The security basics anyone can see from outside: HTTPS, the certificate and when it expires, the security headers browsers use to protect your visitors, and whether your server tells attackers what version it runs.

About a minute. No signup for the summary.

What this check looks at

HTTPSWhether the site runs on HTTPS rather than plain, readable HTTP.
CertificateWhether the TLS certificate is valid and how many days it has left.
Security headersStrict-Transport-Security, Content-Security-Policy, X-Content-Type-Options and Referrer-Policy — with the exact lines to add.
Server version leakWhether your server announces its software and version to anyone who asks.
External domainsEvery outside domain the page contacts — each one receives your visitor's IP address.
The page answersStatus code, redirects and how long the server takes to send the first byte.

Plus the rest of the 30+ checks — every scan runs all of them.

Why it matters

Missing security headers do not break anything you can see — which is why most sites lack them. Each missing one comes with the exact line to add.

An expiring certificate takes a site down overnight. We show how many days are left.

What it does not do

It is not a penetration test: it does not try to break in, log in or scan ports. It checks what every visitor's browser receives.

Questions

Which security headers do you check?

Strict-Transport-Security (HSTS), Content-Security-Policy, X-Content-Type-Options and Referrer-Policy.

Is this a vulnerability scan?

No. It does not attack or probe your site. It reads what your server sends to every visitor and flags what is missing.

Do you give the fix?

Yes — for every missing header, the exact line to add.

Other checks