All six are present, but the script policy allows ’unsafe-inline’. Present is not the same as fine, so no A+.

See it when your security weakens

The test checks HTTPS, your security headers and publicly reachable files. The check below immediately gives you your score out of a hundred; the full scan adds the letter from F to A+. With a subscription we repeat this measurement every month and let you know when your certificate or your domain is about to expire, or when a header disappears that was still there last time.

Verify your security Passive check, not a penetration test

Six headers. One security grade.

Choose a header to see what it tells the browser to do. FlowCore evaluates its value, not merely whether the rule exists.

strict-transport-security

Never come back here over unsecured http. We also read how long that agreement is valid and whether it counts for your subdomains too.

Counts towards the grade from F to A+
Step 1 of 2

Which website would you like to check for security signals?

Start with your domain. We will then ask for your email address to begin the passive security check.

  • No account required
  • Passive check, no attack
  • Result shown in this card

Verify your security

Enter your domain and email address. We read what your server sends along publicly. You immediately get your score, the first points and how many more follow.

  • Your score, right on the screenA score out of a hundred for what your server sends along publicly.
  • The first points, with the value included where possibleBesides “present” also “max-age of 24 months, subdomains included”. You see what it says, not just whether it is there.
  • And how many more followThe check already measures your certificate, TLS version and reachable files; your cookie flags are added in the full report. On a healthy site, there are still about a dozen points behind that.

The check looks at the domain you enter; a path after it is left out. It is passive: it reads the response your site already gives to every visitor, and does not attack any forms, accounts or vulnerabilities. A good result therefore says something about what is visible, not about your code, your passwords or your back-ups.

Explore the full security report

Three sections connect every finding to its severity and the action worth taking first.

How your headers are assessedNot whether they are there, but what is in them.
A letter from F to A+

Built on exactly the six headers that every other header checker counts, so you can put our letter next to theirs.

And why it is capped

All six present but one of them weak, and A+ becomes A. Without that rule, a policy that blocks nothing would score a perfect hundred.

Your script policy, read out in full

Does it contain ’unsafe-inline’, ’unsafe-eval’, an asterisk or data:? Does the policy only run in report mode? That is stated there literally.

How strong your https agreement is

Not just that HSTS is present, but for how many months, whether your subdomains count too, and whether you are ready for the preload list.

What is expiring, with the days included

TLS certificate9 days

Let’s Encrypt, should be renewed well over 30 days before the expiry date

Domain name312 days

Registration continues until the renewal

Below 30 days, a certificate becomes a warning instead of a detail: if it expires, your visitor does not get a slow site but a red screen. If your extension does not publish an expiry date, like .be, the report states that too, and you do not get a reassuring checkmark.

It rarely breaks while you are watching

Most sites do not go down because of an attack, but because of a date. A certificate that was not renewed, a domain name whose invoice ended up at an old address: in both cases everything works, until it stops working from one day to the next.

That is why those two checks also run in the regular check, not only in the paid report. Nine days is too little time to have to buy something first.

A certificate on the wrong name, incidentally, gives the same warning, and any check that only reads the date misses that case.

What else gets measured on your page

Frequently asked questions about website security

What does the website security test check?

The test reads the six security headers your server sends along and what is in them, checks whether http is redirected to https, how long your TLS certificate is still valid, whether your domain registration is expiring, and whether the two files that are most often left open by accident are publicly reachable.

Is this a penetration test?

No. The check is passive and only uses information the website sends back publicly: the same response the browser of every visitor already gets. No forms, accounts or security vulnerabilities are actively attacked.

What does the letter next to my score mean?

The letter runs from F to A+ and counts how many of the six security headers are present. It is deliberately built on exactly those six, so you can put our letter next to that of any other header checker. The score from 0 to 100 covers the whole picture: also your certificate, your redirect, your cookies and exposed files.

Why do I get a warning for a header that is actually present?

Because present is not the same as fine. A Content-Security-Policy that allows ’unsafe-inline’ blocks nothing in practice, and an HSTS of one week has expired before your visitor comes back. That is why we read the value, not just the name. One weak header keeps your letter from going higher than A.

Why do you look at my certificate and my domain name?

Those are the two ways a working website breaks on its own, without anyone changing anything. An expired certificate does not make your site slower, it replaces it with a warning. That is why this point weighs more heavily than any header, and why it also runs in the regular check.

Does a good score mean my website is completely secure?

No. The result is a technical check of visible signals in what your server sends back. It says nothing about your code, your passwords, your back-ups or your hosting, and does not replace a code audit, penetration test or ongoing monitoring.

Is your question not listed? Ask it directly