How secure is your website?
Get a free security score in seconds. We check the public surface of any domain — TLS, headers, cookies, exposed endpoints, and DNS — so you can see your posture before a buyer, auditor, or attacker does.
Real checks against the live site. No signup, no stored URLs.
Five areas of your external surface, scored instantly.
TLS & certificates
TLS version, certificate trust and expiry, and hostname match.
Security headers
CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Cookies & sessions
Secure, HttpOnly, and SameSite flags on your session cookies.
Exposed endpoints
Admin panels, .env backups, .git directories, and open API docs.
DNS & email
SPF, DKIM, DMARC, and CAA records that protect your domain and mail.
Deeper with AppCheck
Auth flows, OWASP Top 10, dependencies, API, and optional source review.
What the number means.
A clean baseline — the obvious doors are shut. What's left is polish before a procurement review.
The basics are mostly in place, but a few material gaps are dragging the score down. Usually fixable in days.
Several issues are visible to anyone scanning your domain. Address the high-severity items before a buyer, auditor, or attacker looks.
Frequently asked questions.
Is this a real security scan?+
Yes. The free check performs live checks against the domain you enter: it inspects the TLS handshake and certificate, response security headers, cookie flags, DNS records (SPF, DKIM, DMARC, CAA), and probes common exposed paths. It's much shallower than an AppCheck audit — it can't exercise authenticated flows, business logic, or source code — but every result comes from the live site, not a heuristic.
Is my URL stored or shared?+
No. The URL is used only to run the check and is not stored, logged, or shared. Because the check runs from our servers, the target domain may see a single request from our IP range.
What does the full AppCheck audit add?+
AppCheck is the real thing: security engineers go through your app the way an attacker would, backed by the best testing tools we have, and re-test every finding before it reaches your report. Beyond this free check it covers authenticated flows, business logic, OWASP Top 10, dependency risk, API security, and optional source-code review — and issues a 0-100 score with a shareable certificate in 1 week.
How often should I check my score?+
A quarterly external check is a reasonable baseline between formal audits. If you deploy frequently or handle sensitive data, AppCheck's continuous monitoring mode refreshes your score and certificate on every pass.
Keep building your security posture.
Turn your score into proof.
A strong external posture is a good start. AppCheck puts engineers — not just tools — on the full surface, then gives you a 0-100 score plus a public certificate you can paste into security questionnaires and your trust page, usually in 1 week.