Free website security checker
Check the basics of how your site protects its visitors: whether it uses HTTPS, whether its SSL/TLS certificate is valid and not about to expire, and which security headers your server sends. It's a quick configuration check, not a penetration test.
What this tool checks
HTTPS
Whether the page ends up on an https:// address after any redirects.
SSL/TLS certificate
Whether the certificate is trusted and matches your domain, which TLS version is used, who issued it and how many days until it expires.
HSTS
The Strict-Transport-Security header, which tells browsers to always use HTTPS for your site.
Content-Security-Policy
A header that limits where scripts and other resources can load from, which helps against cross-site scripting.
Clickjacking protection
X-Frame-Options, or a frame-ancestors rule in your CSP, which stops other sites from embedding your pages invisibly.
Other protective headers
X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
Version disclosure
Server or X-Powered-By headers that reveal software version numbers.
How the check works
We send one normal request to your page, follow any redirects, and read the response headers. Then we open a separate TLS connection to your server and validate the certificate against the standard list of trusted certificate authorities.
The score starts at 100. Not using HTTPS costs 40 points; a missing HSTS header 15; a missing CSP 12; no clickjacking protection 8; a missing X-Content-Type-Options header 6; missing Referrer-Policy or Permissions-Policy 4 each; and a disclosed version number 3. An invalid or expired certificate costs 40, a failed TLS connection 30, and a certificate that expires within 14 or 30 days 10 or 5.
The check looks at whether headers are present, not at how strong their values are — a very permissive CSP still counts as present. It doesn't look for vulnerabilities, outdated software, malware, weak passwords or cookie settings, and it never tries to break in.
Common problems we find
HSTS missing
Very common, even on sites that redirect everything to HTTPS.
No Content-Security-Policy
The most frequently missing header, because it takes some care to set up.
No clickjacking protection
Neither X-Frame-Options nor a frame-ancestors rule.
Certificates close to expiry
Usually because automatic renewal stopped working after a server or DNS change.
Server version on show
Headers like “Server: Apache/2.4.41” or “X-Powered-By: PHP/7.4” that tell attackers what to look for.
Still on HTTP
No HTTPS at all, or HTTPS available but without a redirect from the http:// address.
How to fix them
Set headers where your site is served
Headers are configured in your web server (Nginx add_header, Apache Header set), your CDN (for example Cloudflare), or your host's settings or headers file.
Turn on HSTS once HTTPS works everywhere
Start with Strict-Transport-Security: max-age=31536000. Add includeSubDomains only when every subdomain supports HTTPS.
Introduce CSP gradually
Begin with Content-Security-Policy-Report-Only to see what would be blocked, then switch to enforcing once your policy allows everything the site needs.
Add the simple headers
X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin and X-Frame-Options: DENY (or SAMEORIGIN) rarely break anything.
Automate certificate renewal
Use your host's managed certificates or Let's Encrypt with automatic renewal, and make sure the renewal job still runs after server changes.
Hide version numbers
Turn off version tokens (for example server_tokens off in Nginx, expose_php = Off in PHP).
Frequently asked questions
Is this a penetration test or a vulnerability scan?
No. It checks your HTTPS setup, certificate and security headers — the visible configuration any browser receives. It doesn't try to find or exploit vulnerabilities. For that, hire a qualified security tester.
Can it tell me if my site has been hacked?
No. It doesn't scan for malware, defaced pages or compromised accounts. A good score only means the basics of your transport security are configured.
Does it judge how good my headers are?
Mostly it checks that each header is present. It does recognise a CSP frame-ancestors rule as clickjacking protection, but it doesn't grade the strength of your policies.
Why isn't HSTS checked on my HTTP site?
HSTS only has an effect over HTTPS. If your site isn't on HTTPS, that is the bigger problem, and it's reported instead.
Can adding security headers break my site?
Most headers are safe to add. A Content-Security-Policy can block scripts, styles or embeds your site relies on, so test it in report-only mode first.
Helpful guides
Related free tools
- Website AuditCheck one page for SEO, speed, mobile, accessibility, security, broken links and server problems in a single report.Open Website Audit
- API TesterSend a request to any public API endpoint and see the status code, response time and whether it succeeded.Open API Tester
- SEO CheckerCheck your page title, description, headings, image descriptions, canonical URL, robots.txt and sitemap.Open SEO Checker
Rather have someone fix it for you?
These checks are free and so are the guides. If you'd prefer a person to make the changes, our team offers paid help.