Free Security Scanner

Free website security
scan. Grade A to F in
under 30 seconds.

Instantly check your website or public GitHub repo for security misconfigurations. Security headers, SSL/TLS, exposed files, cookie flags, CORS, DNS email security, and more. No account required.

9 security checks Graded A to F Free — no account needed Results in under 30s

What the scanner checks

9 security check categories, run automatically.

Security Headers

Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options.

SSL / TLS Certificate

Certificate validity, expiry date, and negotiated protocol version (TLS 1.2/1.3 vs deprecated versions).

Cookie Security

Secure, HttpOnly, and SameSite flags on every Set-Cookie response header.

Exposed Sensitive Files

Checks for publicly accessible .env, .git/config, .git/HEAD, database dumps, and backup archives.

CORS Misconfiguration

Detects arbitrary-origin reflection and wildcard origins combined with credentials — the most dangerous CORS setup.

DNS Email Security

SPF and DMARC record presence and policy strength to detect email spoofing exposure.

Directory Listing

Tests common directories for Apache/Nginx autoindex pages that expose your file structure.

Server Version Disclosure

Detects Server and X-Powered-By headers that reveal your exact software versions to attackers.

JS Library Vulnerabilities

Cross-references loaded client-side JavaScript libraries against the Retire.js CVE database.

Scan your site now. It's free.

Enter your URL below. Results in under 30 seconds.

No account required. Results in under 30 seconds.

Connect a public GitHub repository to check for vulnerable dependencies and leaked secrets in commit history. We only request access to public repos, never private ones.

Connect GitHub

Common questions

About the security scanner

What exactly does the free security scan check?

The scanner runs 9 check categories: security headers (Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options), cookie security flags (Secure, HttpOnly, SameSite), TLS/SSL certificate validity and protocol version, exposed sensitive files (.env, .git/config, database backups), CORS misconfiguration, DNS email security (SPF and DMARC records), directory listing, server version disclosure, and client-side JavaScript library vulnerabilities via the Retire.js database.

How long does a website security scan take?

Most scans complete in under 30 seconds. The scanner runs all checks in sequence, each with a strict timeout so a slow or unresponsive check never blocks the others.

Is this a real security audit or just a basic check?

It is an automated passive scan — it checks publicly detectable misconfigurations without attempting any exploits. It does not test for business logic flaws, authentication bypasses, SQL injection, or access control issues. Those require a manual penetration test by a certified security engineer. A full manual audit typically finds 3 to 5 times more issues than automated tools alone.

Is my data safe? What do you store?

We store the target URL, scan results, and your email address (only after you choose to unlock the report). No credentials, session tokens, or sensitive response data are stored. All HTTP requests made during the scan are passive and read-only.

Can I scan someone else's website?

Only scan websites you own or have explicit written authorisation to test. The scanner requires you to confirm this before running. All scans are logged with your IP address and timestamp as an audit trail.

What is the security grade A to F?

Your site receives a score from 0 to 100 based on the checks that pass and fail. Critical issues deduct 25 points, high issues deduct 15 points, medium issues deduct 8 points, and low issues deduct 3 points. Grades: A (90-100), B (75-89), C (60-74), D (40-59), F (below 40).



Need a full security audit, not just a scan?

The automated scan checks publicly visible issues. A manual audit by a CEH-certified engineer covers everything the scanner cannot — authentication, access control, business logic, and injection vulnerabilities.

Book a Free Security Consultation →