Free · No signup · Passive check

Check your website's security in seconds

Enter a website address and get an A to F security grade based on the checks that catch the most common real-world mistakes: missing HTTPS redirects, weak or missing security headers, insecure cookies, mixed content, unpinned third-party scripts and leaked files such as .env or .git.

What this is, and isn't. A passive check: we request the address you enter the way a browser would and inspect the response. It doesn't test for SQL injection, XSS, weak passwords or software bugs, so a good grade is not a guarantee of security. Only scan sites you own or are authorised to test. Scans are rate limited and results are not stored.

How it works

Website Security Checker: 3 simple steps

  1. 1

    Type the website address, for example example.com.

  2. 2

    Tick the confirmation box if you own the site and want the leaked-files check as well.

  3. 3

    Read your grade and open "How to fix this" on anything marked Fix or Improve.

Every problem comes with plain-English explanation and copy-paste fixes for Nginx, Apache, Netlify and Node/Express. The check is passive: we only make ordinary web requests, never attempt to break in, and scans are rate limited. Use it on sites you own or are authorised to test.

Why use it

Built for speed and privacy

  • A to F grade with a clear score
  • Copy-paste fixes for Nginx, Apache, Netlify and Node
  • Checks HTTPS, headers, cookies, mixed content and leaked files
  • Passive, rate limited and nothing is stored
FAQ

Website Security Checker FAQ

The default mode only reads what a normal browser would receive (the page and its response headers). The optional leaked-files check requests a few well-known paths, so only use it on sites you own or have permission to test. Never scan a site you don't have authority over.

No. It is a passive configuration check. It does not test for SQL injection, XSS, weak logins or outdated software, which need an authorised penetration test. A good grade means good baseline hygiene, not that a site is unhackable.

A is 90 or above, B 80 or above, C 65 or above, D 50 or above and F below that. The score is weighted towards the issues that matter most, such as HTTPS, HSTS, a Content-Security-Policy and exposed secrets.

No. Results are shown to you and not saved. We keep only an anonymised, hashed counter to enforce rate limits.

Want your security issues fixed and monitored?

We harden servers, deployments and applications, and keep them patched.