Rudra Analyzer

Free website security checker

Check the basics of how your site protects its visitors: whether it uses HTTPS, whether its SSL/TLS certificate is valid and not about to expire, and which security headers your server sends. It's a quick configuration check, not a penetration test.

Enter one page, for example https://yourwebsite.com or https://yourwebsite.com/pricing.

What this tool checks

  • HTTPS

    Whether the page ends up on an https:// address after any redirects.

  • SSL/TLS certificate

    Whether the certificate is trusted and matches your domain, which TLS version is used, who issued it and how many days until it expires.

  • HSTS

    The Strict-Transport-Security header, which tells browsers to always use HTTPS for your site.

  • Content-Security-Policy

    A header that limits where scripts and other resources can load from, which helps against cross-site scripting.

  • Clickjacking protection

    X-Frame-Options, or a frame-ancestors rule in your CSP, which stops other sites from embedding your pages invisibly.

  • Other protective headers

    X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

  • Version disclosure

    Server or X-Powered-By headers that reveal software version numbers.

How the check works

We send one normal request to your page, follow any redirects, and read the response headers. Then we open a separate TLS connection to your server and validate the certificate against the standard list of trusted certificate authorities.

The score starts at 100. Not using HTTPS costs 40 points; a missing HSTS header 15; a missing CSP 12; no clickjacking protection 8; a missing X-Content-Type-Options header 6; missing Referrer-Policy or Permissions-Policy 4 each; and a disclosed version number 3. An invalid or expired certificate costs 40, a failed TLS connection 30, and a certificate that expires within 14 or 30 days 10 or 5.

The check looks at whether headers are present, not at how strong their values are — a very permissive CSP still counts as present. It doesn't look for vulnerabilities, outdated software, malware, weak passwords or cookie settings, and it never tries to break in.

Common problems we find

  • HSTS missing

    Very common, even on sites that redirect everything to HTTPS.

  • No Content-Security-Policy

    The most frequently missing header, because it takes some care to set up.

  • No clickjacking protection

    Neither X-Frame-Options nor a frame-ancestors rule.

  • Certificates close to expiry

    Usually because automatic renewal stopped working after a server or DNS change.

  • Server version on show

    Headers like “Server: Apache/2.4.41” or “X-Powered-By: PHP/7.4” that tell attackers what to look for.

  • Still on HTTP

    No HTTPS at all, or HTTPS available but without a redirect from the http:// address.

How to fix them

  1. Set headers where your site is served

    Headers are configured in your web server (Nginx add_header, Apache Header set), your CDN (for example Cloudflare), or your host's settings or headers file.

  2. Turn on HSTS once HTTPS works everywhere

    Start with Strict-Transport-Security: max-age=31536000. Add includeSubDomains only when every subdomain supports HTTPS.

  3. Introduce CSP gradually

    Begin with Content-Security-Policy-Report-Only to see what would be blocked, then switch to enforcing once your policy allows everything the site needs.

  4. Add the simple headers

    X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin and X-Frame-Options: DENY (or SAMEORIGIN) rarely break anything.

  5. Automate certificate renewal

    Use your host's managed certificates or Let's Encrypt with automatic renewal, and make sure the renewal job still runs after server changes.

  6. Hide version numbers

    Turn off version tokens (for example server_tokens off in Nginx, expose_php = Off in PHP).

Frequently asked questions

Is this a penetration test or a vulnerability scan?

No. It checks your HTTPS setup, certificate and security headers — the visible configuration any browser receives. It doesn't try to find or exploit vulnerabilities. For that, hire a qualified security tester.

Can it tell me if my site has been hacked?

No. It doesn't scan for malware, defaced pages or compromised accounts. A good score only means the basics of your transport security are configured.

Does it judge how good my headers are?

Mostly it checks that each header is present. It does recognise a CSP frame-ancestors rule as clickjacking protection, but it doesn't grade the strength of your policies.

Why isn't HSTS checked on my HTTP site?

HSTS only has an effect over HTTPS. If your site isn't on HTTPS, that is the bigger problem, and it's reported instead.

Can adding security headers break my site?

Most headers are safe to add. A Content-Security-Policy can block scripts, styles or embeds your site relies on, so test it in report-only mode first.

Helpful guides

Related free tools

Rather have someone fix it for you?

These checks are free and so are the guides. If you'd prefer a person to make the changes, our team offers paid help.