How secure is your website?
Get a free security score in seconds. We check the public surface of any domain — TLS, headers, cookies, exposed endpoints, and DNS — so you can see your posture before a buyer, auditor, or attacker does.
Real checks against the live site. No signup, no stored URLs.
Five areas of your external surface, scored instantly.
TLS & certificates
TLS version, certificate trust and expiry, and hostname match.
Security headers
CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Cookies & sessions
Secure, HttpOnly, and SameSite flags on your session cookies.
Exposed endpoints
Admin panels, .env backups, .git directories, and open API docs.
DNS & email
SPF, DKIM, DMARC, and CAA records that protect your domain and mail.
Deeper with AppCheck
Auth flows, OWASP Top 10, dependencies, API, and optional source review.
What the number means.
A clean external baseline. Most items are in place; a few tightenings may still be worth doing before a procurement review.
The basics are mostly in place, but a few material gaps are dragging the score down. Usually fixable in days.
Several issues are visible to anyone scanning your domain. Address the high-severity items before a buyer, auditor, or attacker looks.
Frequently asked questions.
Is this a real security scan?+
Yes. The free check performs live checks against the domain you enter: it inspects the TLS handshake and certificate, response security headers, cookie flags, DNS records (SPF, DKIM, DMARC, CAA), and probes common exposed paths. It's shallower than a manual audit — it can't exercise authenticated flows, business logic, or source code — but every result is based on real data from the live site.
Is my URL stored or shared?+
No. The URL is used only to run the check and is not stored, logged, or shared. Because the check runs from our servers, the target domain may see a single request from our IP range.
What does the full AppCheck audit add?+
AppCheck is a semi-manual audit by our security team. Beyond the external surface, it covers authenticated flows, business logic, OWASP Top 10, dependency risk, API security, and an optional source-code review — and issues a 0-100 score with a shareable certificate.
How often should I check my score?+
A quarterly external check is a reasonable baseline between formal audits. If you deploy frequently or handle sensitive data, AppCheck's continuous monitoring mode refreshes your score and certificate on every pass.
Keep building your security posture.
Information security program generator
Answer ten questions and get a 17-section security program your SOC 2 or ISO 27001 audit can work from.
Turn your score into proof.
A strong external posture is a good start. AppCheck goes deeper and gives you a 0-100 score plus a public certificate you can paste into security questionnaires and your trust page.