← Back to all tools

Free tool · 05

Security Audit

Paste any URL. We check the security headers a browser sees — HTTPS, HSTS, CSP, clickjacking and MIME protection, cookie flags — and probe for exposed .git and .env files. Read-only, non-intrusive.

This is a passive header scan — we only read what any browser receives, we don't attack anything. Need a full penetration test or a hardened deployment? Talk to our engineering team.

A free website security checker for the basics that get sites hacked

Most sites aren't breached by exotic exploits — they're breached through misconfigurations anyone can see: missing security headers, an exposed .env or .git folder, a login with no protection. This free security audit reads exactly what a browser receives from your site and grades the parts that matter: HTTPS and HSTS, Content-Security-Policy, clickjacking and MIME protection, cookie flags and server-version disclosure.

It also probes for commonly-exposed files like .git and .env that can leak source code and credentials. Everything is read-only and non-intrusive — we only look at what's already public, and never attack anything — and you get a letter grade with clear remediation steps. For advertisers there's a specific stake: a compromised site can get your domain banned from Meta and Google Ads.

What you get

Frequently asked questions

What does the security audit check?
The security headers a browser receives — HTTPS, HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — plus cookie flags, server-version disclosure and exposed .git/.env files.
Is this a penetration test?
No. It's a passive, read-only header and configuration scan. A full penetration test actively probes for vulnerabilities and is a separate, authorized engagement — which our team can run for you.
Is it safe and legal to run on my site?
Yes. The scan only reads publicly-served responses, the same way a browser does. It doesn't attempt to log in, exploit or damage anything.
What is a good security grade?
An A means the common browser-level protections are in place. Lower grades usually mean missing headers — quick fixes that meaningfully reduce clickjacking, XSS and data-exposure risk.
Is the security audit free?
Yes, the instant grade is free with no login. For a full penetration test or a hardened deployment, talk to our engineering team.
Does it store my results?
No. The instant scan isn't saved to an account — we read your site's public responses to produce the grade and don't retain them.

Other free tools

SEO Audit→QR Code Generator→