Skip to content

Free · No signup · Instant

Is your website configured securely?

Enter your address. We check the certificate, whether insecure requests are forced to HTTPS, and the security headers browsers rely on — then tell you precisely what is missing.

Loads your homepage once, exactly as a browser does. No scanning, nothing stored.

Also worth two seconds: can someone send email pretending to be you? 81% of Ocala businesses can.

Why it matters

Your website is the first thing anyone tests

Not by attacking it — by looking at it. These settings are visible to anyone, which makes them the cheapest possible reconnaissance and the easiest thing to get right.

  • A version number is an invitation

    A server that announces its exact version tells an attacker which known vulnerabilities to try first. It removes the guesswork before they have even started.

  • Clickjacking uses your own site

    Without frame protection, your pages can be loaded invisibly inside somebody else's and used to capture clicks your customers never meant to make.

  • Redirecting is not the same as enforcing

    A redirect still allows that very first insecure request. HSTS is what tells the browser never to try HTTP again.

Questions

About this check

What exactly does this check?

Your HTTPS certificate and how long it has left, whether insecure HTTP requests are redirected to HTTPS, and the response headers browsers use to prevent clickjacking, MIME-type confusion and downgrade attacks — HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy. It also flags whether your server is publishing its exact software version.

Is this a vulnerability scan?

No, and deliberately so. It loads your homepage once, exactly as a browser would, plus one request to check the HTTP redirect and one TLS handshake for the certificate. It does not probe for admin pages, look for exposed files, test for injection, or attempt any login. Scanning somebody else's property without permission is not something we will build a public button for.

Does a good grade mean my website is secure?

It means it is well configured at the front door. It says nothing about out-of-date plugins, weak passwords, your hosting account, or what happens behind a login. Treat it as one useful signal rather than a clean bill of health.

We use WordPress. Why are we failing?

Most WordPress hosts ship with none of these headers set, and many publish the PHP and server version by default. It is rarely the fault of the site itself — it is the host configuration, and it is usually fixable in the control panel or with a few lines in .htaccess.

Could fixing these break my site?

A strict Content Security Policy can, if it blocks a script your own site depends on — an analytics tag, a booking widget, a chat tool. That is why it should be introduced in report-only mode first. The other headers are low risk.

Do you store the domain I enter?

No. The check runs when you press the button and the result is returned to your browser. Nothing is kept and nothing is emailed to us.

Want the whole picture?

These two tools cover what the outside world can see. The free assessment covers what it cannot — backups, Microsoft 365 settings, patching and what your network exposes.

Book the free assessment