Home / Tools / Website security audit

See what your website tells attackers about itself.

Paste your address. In about ten seconds you get a graded report of your encryption, certificates, security headers, email spoofing protection and third-party code, with a plain-English fix for each problem. No signup.

Scan sites you own, or have permission to check. We only read what the server tells every visitor. No attack traffic, no probing. Terms · How to opt out

What the free scan covers, and what it does not

This is the honest version. The scan reads what your server publishes to every visitor, which is a great deal more than most people expect and still not everything. The right-hand column says what each answer means.

WhatFree scanHow
Encryption and certificatesYesTLS versions, ciphers, certificate chain, expiry, trust
Security headersYesContent policy strength, HSTS, framing, sniffing, referrer
CookiesYesSecure, HttpOnly and SameSite, judged by what the cookie holds
Email spoofingYesSPF, DMARC, MTA-STS and certificate authority pinning
Third-party codeYesWho runs code on your pages, and whether it is version-locked
Known-vulnerable librariesYesYour JavaScript checked against the OSV database
Subdomain takeoverYesDNS records pointing at services that no longer exist
Login and access controlNoNeeds authorised testing
Data belonging to other usersNoNeeds authorised testing
Injection and application flawsNoNeeds authorised testing
Exposed config files and backupsNoNeeds proof you control the domain
Open ports and exposed servicesNoNeeds authorised testing

The four items marked no are not missing features. Finding them requires attacking a site, and doing that without the owner’s written permission is a criminal offence.

Why we give this away

Most security tools that offer a free scan use it to collect an email address, then send a report thin enough that you have to book a call to understand it. This one gives you the whole report, immediately, with the fixes written out.

We do that because the honest limits of a passive scan make the case for the paid work better than any sales page could. When the report says it cannot see whether your login can be bypassed, that is not a teaser. It is the actual boundary of what anyone can check without permission, and it is exactly the work a real review does.

If the report comes back clean, good. You have lost ten seconds and gained a document you can hand to a client or an auditor.

  • Whole report, no email required
  • Every finding says why it matters and how to fix it
  • Optional hardening never counts against your grade
  • Ordered by importance, then by how little work it is
  • We scan our own site with it and publish the result
What a real security review involves

Common questions

Yes, and there is no signup, no email wall and no credit card. The scan costs us a fraction of a penny to run. We publish it because a fair number of people who see their results decide they want a proper security review, and that is work we sell.

Want someone to actually try the handle?

A scan reads the outside of your site. A review tests whether the locks hold, under a signed authorisation. Alex Novak replies within one business day.

Get an estimate