Free Tools

Quick Website Security Checks

Use focused, lightweight checks for individual website security signals. For CMS detection, vulnerability applicability, exposure review, DNS/email posture, third-party inventory, and report exports, run the full CMS audit.

Security Headers Checker

Check whether a public URL sends common browser security headers such as CSP, HSTS, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

SSL TLS Checker

Review HTTPS reachability, certificate validity, hostname match, expiry window, TLS versions, and HTTP-to-HTTPS redirect behavior.

Robots.txt and Sitemap Checker

Check robots.txt, sitemap references, reachable sitemap URLs, and sensitive-looking paths advertised to crawlers.

Cookie Flags Checker

Review homepage Set-Cookie headers for Secure, HttpOnly, SameSite, and basic cookie hygiene indicators.

Mixed Content Checker

Check whether an HTTPS homepage references insecure HTTP scripts, styles, media, iframes, or form actions.

Domain Redirect Checker

Review apex, www, HTTP, and HTTPS variants for redirect behavior and canonical destination consistency.

Technology Fingerprint Checker

Identify public CMS, CDN, server, analytics, and JavaScript library hints from the homepage response.

Email Security Checker

Review SPF, DMARC, MX, and related email security signals for a domain.

CMS Detector

Identify public CMS signals and confidence indicators without generating a full report.