Web security check
Reads your site's HTTPS response headers and assesses the protections the browser applies to your visitors.
- HTTPS, HSTS and redirection
- CSP, clickjacking, MIME type
- Cookie attributes
Free tools
Real technical checks, free and without sign-up. You enter a domain, we read what is already public and hand you a readable report with the exact fix for each finding.
Reads your site's HTTPS response headers and assesses the protections the browser applies to your visitors.
Reads your public DNS records and checks whether your domain can be spoofed in a phishing campaign.
Measurement of real load time and Core Web Vitals metrics, with blocking points ranked by impact.
In development.
They observe only what your server and your DNS zone already publish to everyone: one HTTPS request to your home page, a few DNS lookups. Nothing is sent to your users, no account is tested, no port is scanned, no vulnerability is exploited. They are therefore surface indicators: they spot missing or dangerous configuration, but they replace neither an application audit, nor a penetration test, nor a code review. A good score does not mean your system is secure — it means these particular checks pass, at this moment.
Coming soon
A configuration that is correct today can be broken tomorrow by a release, a change of supplier or an expired certificate. We are preparing a subscription for continuous checking: repeated runs, history, email alerts and exportable reports. It is not open yet.
Be told when it opens