One input, 20+ checks — TLS, headers, exposed files, DNS, WordPress. Within half a minute you'll see results and you can email yourself a PDF report with concrete remediation steps.
No signup, just the URL. No email — we ask for that only when you request the PDF report.
Passively. TLS, security headers, DNS (SPF/DMARC), exposed files, CMS versions, open ports.
You'll see all findings right on the site. Request the PDF report via the button — every finding has an explanation, impact and concrete remediation step.
We probe your domain with the same methods every attacker starts with. If we find something, we explain it for non-experts too.
Without CSP any XSS payload can run third-party code at your customers.
Content-Security-Policy: (not present)
An attacker downloads your entire source. It may contain database credentials or API keys.
GET /.git/HEAD → 200 OK
An outdated protocol with known weaknesses, and a PCI-DSS compliance issue.
openssl s_client -tls1 → handshake OK
Anyone can send emails as your domain. Spam reaches your clients.
_dmarc: v=DMARC1; p=none
4 vulnerabilities have been patched since your version. Core auto-updates are probably disabled.
generator: WordPress 6.2
Enter a domain, look at the results, and email yourself a PDF report showing where your site currently has open doors — one click.