Skip to content
Free Website Security Scanner

Find security misconfigurations before your customers — or an attacker — do.

Scan any domain you own for missing security headers, SSL/TLS certificate problems, DNS and email-authentication gaps, and insecure redirect or cookie setup. Most scans complete in seconds (up to 60s for slow targets), no account or credit card required.

This is a security misconfiguration scanner, not a penetration test. It reads publicly observable configuration — response headers, certificates, DNS records, cookie flags, redirects and detectable technology — and never attempts exploitation. It does not run CVE or exploit scans, WordPress plugin vulnerability scans, malware scans, or AI-based analysis.

A handful of gaps show up on almost every first scan — an HSTS header that was never added being one of the most common. See what that looks like on the missing HSTS finding page.

Check Your Website Security

Get a detailed security report in seconds. No credit card required.

Real-Time Security Scan

Analyze your infrastructure in seconds. No installation required.

What the scan actually checks

Four categories, all read from publicly observable configuration. Each links to a dedicated deep-dive if you want the detail behind a single category.

Security Headers

Checks whether the response sends the headers browsers rely on to enforce transport security and stop common injection and clickjacking techniques.

  • HTTP Strict Transport Security (HSTS)
  • Content-Security-Policy (CSP)
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy
  • Deprecated / legacy headers still being served
Full security headers checker

SSL / TLS

Checks the certificate and negotiated protocol actually presented to a visitor's browser, not just whether HTTPS is present.

  • Certificate expiry countdown
  • Hostname / SAN match
  • Self-signed or untrusted issuer detection
  • Weak or deprecated TLS protocol versions
  • Certificate chain completeness
Full SSL/TLS checker

DNS & Email Authentication

Checks DNS resolution health and the records that stop your domain from being spoofed in email, plus DNS integrity signals.

  • DNS resolution (A/AAAA/CNAME)
  • SPF record presence and syntax
  • DMARC policy presence
  • CAA record presence
  • DNSSEC signing presence
Full DNS security checker

Redirects, Cookies & Technology

Checks how the site is actually wired up: whether HTTP forces HTTPS, how cookies are flagged, and what's running underneath.

  • HTTP → HTTPS redirect configuration
  • Cookie Secure / HttpOnly / SameSite flags
  • Technology stack detection (server, CMS, frameworks in use)
How these roll into your score

How your score is calculated

Every check above rolls into a single numeric score and letter grade, so you can see overall posture at a glance and still drill into exactly what moved it. The full scoring methodology — how categories are weighted and how grade boundaries are set — is documented on its own page.

See the scoring methodology

Frequently asked questions

Is this a vulnerability scanner or a penetration test?

Neither. It's a security misconfiguration scanner: it reads publicly observable configuration such as response headers, certificates, DNS records and cookie flags. It does not attempt exploitation, and it does not run CVE, exploit, WordPress plugin, or malware scans.

What does the scanner check?

Security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, plus deprecated headers), SSL/TLS (expiry, hostname match, self-signed/weak protocol detection, chain), DNS (resolution, SPF, DMARC, CAA, DNSSEC presence), cookie flags, redirect/HTTPS configuration, and technology detection.

How is the security score calculated?

Each check category contributes to an overall score and letter grade. The full methodology — how categories are weighted and how the grade boundaries are set — is documented on the Website Security Score page.

Do I need an account to scan my site?

No. The scanner above runs without a login or credit card. Creating a free account adds continuous rescans and removes the shared per-IP scan limit.

Can I scan a domain I don't own?

The scanner only reads publicly available information and performs no exploitation, but you must confirm you own or are authorized to assess the target domain before a scan runs.