Skip to content
Albright Labs

Free Audit · Security

Is your site served the right way?

Most site security starts with boring, invisible configuration: everything on HTTPS, a handful of headers telling browsers what to allow, and no HTTP assets sneaking onto secure pages. This audit checks the ones that matter and tells you which are missing.

  • HTTPS coverage across every page we crawl, plus mixed content
  • HSTS, Content-Security-Policy and X-Frame-Options
  • X-Content-Type-Options and Referrer-Policy
  • A per-page table, because coverage is rarely uniform

Run your free audit

Two fields. We send your security report by email.

Free, no account required. We use your email only to send your report and follow up about your results.

What this is

The front door, not the building.

This audit reads how your pages are served and which security headers they send. Everything it flags is real, and most of it is fixed in server configuration rather than in your code, which makes it some of the cheapest security work available to you.

What it is not is a vulnerability scan. It does not test your application logic, your dependencies, your authentication, your database, or your admin. A clean score means the front door is fitted properly. It says nothing about the locks inside, and we would rather tell you that than sell you a green tick.

How it works

From URL to report.

01

Enter your URL

Your site address and your email. That is the whole form.

02

We read the responses

We crawl your live pages and inspect the protocol and security headers each one returns.

03

Get your report

A score per header, what it does, and which pages are missing it.

Common questions

Security check FAQs

No. It reads how your pages are served and which security headers they send. It does not probe your application, your dependencies, your logins or your data. Those are worth doing and they are a different exercise, done by a person.

It means your transport and headers are configured well, which is a genuine and often-missing foundation. It does not mean your site is secure, and we will not tell you it does. Plenty of thoroughly compromised sites score well here.

A secure page loading an image, script or stylesheet over plain HTTP. Browsers either block it or warn about it, and it quietly undoes the encryption you thought you had. It is also usually a one-line fix, which is the best combination a finding can have.

Common rather than catastrophic. CSP is the most powerful header here and the most work to get right, because a strict policy can break a working site. It is worth doing deliberately, not in a hurry.

Because coverage is often not uniform. Headers set at the app level can be missing from anything served by a different route, a CDN rule, or a legacy subdirectory. The per-page table is where you find that.

Usually, and usually quickly. Most of these are server or CDN configuration rather than code, and the ones that are not, like a real CSP, are the ones worth planning.

Security Check

Want this configured properly?

Most of what this finds is server configuration, which means it is quick to fix and easy to leave broken. We do it, and we keep it that way.

Talk to us

A senior engineer reads it and replies within one business day.