Free tool · 05
Security Audit
Paste any URL. We check the security headers a browser sees — HTTPS, HSTS, CSP, clickjacking and MIME protection, cookie flags — and probe for exposed .git and .env files. Read-only, non-intrusive.
This is a passive header scan — we only read what any browser receives, we don't attack anything. Need a full penetration test or a hardened deployment? Talk to our engineering team.
A free website security checker for the basics that get sites hacked
Most sites aren't breached by exotic exploits — they're breached through misconfigurations anyone can see: missing security headers, an exposed .env or .git folder, a login with no protection. This free security audit reads exactly what a browser receives from your site and grades the parts that matter: HTTPS and HSTS, Content-Security-Policy, clickjacking and MIME protection, cookie flags and server-version disclosure.
It also probes for commonly-exposed files like .git and .env that can leak source code and credentials. Everything is read-only and non-intrusive — we only look at what's already public, and never attack anything — and you get a letter grade with clear remediation steps. For advertisers there's a specific stake: a compromised site can get your domain banned from Meta and Google Ads.
What you get
- Security headersHTTPS, HSTS, CSP, X-Frame-Options, X-Content-Type-Options and more.
- Exposed-file probeChecks for public .git and .env that leak code and secrets.
- Cookie & disclosure checksCookie flags and leaked server / framework versions.
- Letter grade + fixesA clear grade with step-by-step remediation guidance.
- Read-only & safeNon-intrusive — we only read what any browser already sees.
- Free, no loginInstant results, nothing stored on our side.
Frequently asked questions
- What does the security audit check?
- The security headers a browser receives — HTTPS, HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — plus cookie flags, server-version disclosure and exposed .git/.env files.
- Is this a penetration test?
- No. It's a passive, read-only header and configuration scan. A full penetration test actively probes for vulnerabilities and is a separate, authorized engagement — which our team can run for you.
- Is it safe and legal to run on my site?
- Yes. The scan only reads publicly-served responses, the same way a browser does. It doesn't attempt to log in, exploit or damage anything.
- What is a good security grade?
- An A means the common browser-level protections are in place. Lower grades usually mean missing headers — quick fixes that meaningfully reduce clickjacking, XSS and data-exposure risk.
- Is the security audit free?
- Yes, the instant grade is free with no login. For a full penetration test or a hardened deployment, talk to our engineering team.
- Does it store my results?
- No. The instant scan isn't saved to an account — we read your site's public responses to produce the grade and don't retain them.