Is your website set up securely?
Missing security headers and exposed files are an open door. Check it free, passively, without stressing your site.
Run the free checkAn open door you can't see
Many sites look fine but miss the basics that attackers and scanners spot instantly. These three are the most common:
No security headers
The browser gets no instructions to protect your visitors.
Exposed files
Config or source code accidentally left public.
No forced https
Traffic that can still run over insecure http.
Run your free security check now
Enter your domain and email. We only run passive checks on your own site, nothing intrusive. Instant result.
What we check
- Security headers
HSTS, CSP, nosniff and clickjacking protection.
- Forced https
Redirects http traffic to the secure version.
- Exposed files
Files like .env or .git that should never be public.
- Cookie flags
Whether cookies are set with Secure and HttpOnly.
- Version leaks
Whether your server or framework reveals its version.
More than security alone
This check looks at your security. The full report screens your whole website: security, speed, SEO and more, with a concrete action plan.
To the full scan