Free Audit · Security
Is your site served the right way?
Most site security starts with boring, invisible configuration: everything on HTTPS, a handful of headers telling browsers what to allow, and no HTTP assets sneaking onto secure pages. This audit checks the ones that matter and tells you which are missing.
- HTTPS coverage across every page we crawl, plus mixed content
- HSTS, Content-Security-Policy and X-Frame-Options
- X-Content-Type-Options and Referrer-Policy
- A per-page table, because coverage is rarely uniform
Run your free audit
Two fields. We send your security report by email.
What this is
The front door, not the building.
This audit reads how your pages are served and which security headers they send. Everything it flags is real, and most of it is fixed in server configuration rather than in your code, which makes it some of the cheapest security work available to you.
What it is not is a vulnerability scan. It does not test your application logic, your dependencies, your authentication, your database, or your admin. A clean score means the front door is fitted properly. It says nothing about the locks inside, and we would rather tell you that than sell you a green tick.
How it works
From URL to report.
Enter your URL
Your site address and your email. That is the whole form.
We read the responses
We crawl your live pages and inspect the protocol and security headers each one returns.
Get your report
A score per header, what it does, and which pages are missing it.
Common questions
Security check FAQs
No. It reads how your pages are served and which security headers they send. It does not probe your application, your dependencies, your logins or your data. Those are worth doing and they are a different exercise, done by a person.
It means your transport and headers are configured well, which is a genuine and often-missing foundation. It does not mean your site is secure, and we will not tell you it does. Plenty of thoroughly compromised sites score well here.
A secure page loading an image, script or stylesheet over plain HTTP. Browsers either block it or warn about it, and it quietly undoes the encryption you thought you had. It is also usually a one-line fix, which is the best combination a finding can have.
Common rather than catastrophic. CSP is the most powerful header here and the most work to get right, because a strict policy can break a working site. It is worth doing deliberately, not in a hurry.
Because coverage is often not uniform. Headers set at the app level can be missing from anything served by a different route, a CDN rule, or a legacy subdirectory. The per-page table is where you find that.
Usually, and usually quickly. Most of these are server or CDN configuration rather than code, and the ones that are not, like a real CSP, are the ones worth planning.
More free audits
SEO Audit
Can search engines make sense of your pages?
Accessibility Audit
Can everyone actually use your site?
All free audits
Thirteen audits, all free to run, no signup.
The complete pass
Full Site Audit
All ten pillars scored across up to thirty pages. Free to run, $49 to unlock the full report. The free audits each cover one part of it.
Security Check
Want this configured properly?
Most of what this finds is server configuration, which means it is quick to fix and easy to leave broken. We do it, and we keep it that way.
A senior engineer reads it and replies within one business day.