Skip to content
Website security

Scan your site for
security gaps.

A free passive check of your site's security posture. No attacks, safe on any URL.

Takes a few seconds. No signup.
What we check

The basics, checked honestly.

We fetch your URL and inspect what's externally observable, then group the findings by area with concrete fixes, and a path to a full review when you want to go deeper.

  • Transport security: HTTPS enforcement and HSTS, so traffic can't be downgraded or intercepted.
  • Security headers: Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • Cookies: Secure, HttpOnly and SameSite flags on session and tracking cookies.
  • Information leakage: server/version banners and framework fingerprints that help attackers.
  • Content integrity: mixed content (HTTPS pages loading resources over plain http).
FAQ

Security scan: common questions.

What the scan covers and how it differs from a penetration test.

Go deeper

Want a full security review?

A full engagement adds active testing, threat modeling, dependency and infrastructure review, and a prioritized remediation plan with engineering support.

Free downloads
delivered by email.

Pick a document and we email you the PDF.

The Prompt Injection Field GuideDirect and indirect injection explained, with the layered defenses that actually hold.

One email when there's something genuinely useful. Unsubscribe in one click.

Website security scan: free passive posture check · SDEN