Free · No obligation
Free website security checkup.
Send us your website address and we’ll run a 10-point external check, then email you a short report in plain language. Free, no strings attached.
What we check
Ten things any attacker looks at first — all verifiable from the outside, without touching your server.
- 01
HTTPS & TLS configuration
Valid certificate, modern protocol versions, no weak ciphers.
- 02
Security headers
CSP, HSTS, frame and content-type protections on your responses.
- 03
Software version exposure
CMS and server version numbers your site leaks to attackers.
- 04
Outdated JavaScript libraries
Known-vulnerable library versions visible in your pages.
- 05
Mixed content
Insecure resources loaded into otherwise secure pages.
- 06
Email spoofing protection
SPF, DKIM and DMARC records on your sending domain.
- 07
Exposed files & listings
Publicly reachable backups, configs or open directory indexes.
- 08
Cookie security
Secure, HttpOnly and SameSite flags on your session cookies.
- 09
Admin panel exposure
Login pages reachable — and brute-forceable — from the open internet.
- 10
Domain & DNS hygiene
Dangling records, expiring certificates, lookalike risks.
These are non-intrusive checks of publicly visible information — the same things any browser or search engine can see. We never test beyond that without your written permission.
How it works
- 01
You send your address
The form below takes thirty seconds. Add a note if something specific worries you.
- 02
We run the checks
External and passive only — we read what your site already shows any visitor. We never probe, exploit or disrupt anything.
- 03
You get the report
Within two business days: a short email in plain language — what’s solid, what’s risky, and what we’d fix first. A quote only if you ask for one.