See what your website tells attackers about itself.
Paste your address. In about ten seconds you get a graded report of your encryption, certificates, security headers, email spoofing protection and third-party code, with a plain-English fix for each problem. No signup.
Scan sites you own, or have permission to check. We only read what the server tells every visitor. No attack traffic, no probing. Terms · How to opt out
What the free scan covers, and what it does not
This is the honest version. The scan reads what your server publishes to every visitor, which is a great deal more than most people expect and still not everything. The right-hand column says what each answer means.
The four items marked no are not missing features. Finding them requires attacking a site, and doing that without the owner’s written permission is a criminal offence.
Why we give this away
Most security tools that offer a free scan use it to collect an email address, then send a report thin enough that you have to book a call to understand it. This one gives you the whole report, immediately, with the fixes written out.
We do that because the honest limits of a passive scan make the case for the paid work better than any sales page could. When the report says it cannot see whether your login can be bypassed, that is not a teaser. It is the actual boundary of what anyone can check without permission, and it is exactly the work a real review does.
If the report comes back clean, good. You have lost ten seconds and gained a document you can hand to a client or an auditor.
- Whole report, no email required
- Every finding says why it matters and how to fix it
- Optional hardening never counts against your grade
- Ordered by importance, then by how little work it is
- We scan our own site with it and publish the result
Common questions
Yes, and there is no signup, no email wall and no credit card. The scan costs us a fraction of a penny to run. We publish it because a fair number of people who see their results decide they want a proper security review, and that is work we sell.
Whether your connection is properly encrypted and your certificate is healthy, which security headers you send, how your cookies are protected, whether someone can send email pretending to be your domain, whether any of the JavaScript on your page has publicly known security problems, whether a subdomain could be taken over, and whether internal error messages or file listings are visible. Around forty checks in total.
No. Every request the scanner makes is one an ordinary visitor's browser would make. We read your homepage, your certificate, your headers and your public DNS records. We do not send attack traffic, we do not test for exploits, and we do not go looking for hidden files. It puts less load on your server than one person browsing your site.
Technically yes, because everything we look at is public. But our terms ask you to scan sites you own or have permission to check, and we rate-limit accordingly. If you are checking a supplier or a potential acquisition, that is a reasonable use.
No, and this is the most important thing on the page. A clean report means the outside of your site is configured correctly. It says nothing about whether your login can be bypassed, whether one customer can read another's data, or whether your database is exposed. Those need real testing, with permission.
Because finding them means attacking the site, and attacking a website without the owner's written permission is a criminal offence in the UK under the Computer Misuse Act and prosecutable under several US state laws. No tool that accepts a pasted address from a stranger can legally do it. Any tool claiming otherwise is either not doing what it says or is exposing itself and you.
Each problem carries a weight based on how much damage it could enable. Missing encryption or an untrusted certificate weighs heavily; a missing optional header barely registers. Optional hardening items are listed but never count against you, because marking a well-run site down for not doing something optional makes the grade useless.
Possibly not wrong, but worth reading closely. The most common reason for a B on an otherwise well-run site is a missing Content-Security-Policy, which is genuinely the hardest header to add and the one that matters most. If you disagree with a specific finding, tell us. We would rather fix the scanner than defend it.
We cache the report for fifteen minutes so a refresh is instant, and keep it for thirty days. Your IP address is hashed when we receive it and the raw value is gone within a day. We never store the contents of anything we fetch from your site.
Publish a DNS TXT record at _eazescan-optout on your domain with the value "opt-out" and we stop within 24 hours, or email hello@dearhearth.com. The details are on our scanner page.
Want someone to actually try the handle?
A scan reads the outside of your site. A review tests whether the locks hold, under a signed authorisation. Alex Novak replies within one business day.
