FREE · 135 CHECKS · NO SIGNUP

Free Security Scan

Run 135 deterministic security checks across 17 categories — TLS, security headers, CSP, hidden file exposure, cloud bucket detection, subdomain takeover, and more. No payload sent, no permission needed, no signup. Mozilla Observatory aligned, 30-second checkup for any site you own.

Try: · · ·
135 checks17 categoriesMozilla Observatory aligned0 data retained

What we check

135 deterministic checks across 17 categories — no payload, no permission needed.

TLS / HTTPS
Cert chain, ciphers, TLS 1.3 readiness
HSTS / Mixed Content
Strict-Transport-Security and HTTPS-only assets
HTTP Security Headers
X-Frame-Options, X-Content-Type, Referrer-Policy
Cookies & Sessions
Secure / HttpOnly / SameSite flag audit
CSP / SRI
Content-Security-Policy + Subresource Integrity
CORS
Access-Control-Allow-Origin posture
Hidden file exposure
.git, .env, .DS_Store, config leaks
Source maps
Leaked .map files exposing source
Cloud bucket detection
Public S3 / GCS / Azure exposure
Subdomain takeover
Dangling CNAMEs and abandoned services
DNS / DNSSEC
DNS records, DNSSEC chain validation
Email security
SPF, DMARC, DKIM, MTA-STS posture
Open redirect
Unsafe ?next= / ?url= redirect surfaces
Tracking & Privacy
Third-party trackers and fingerprinting
OG / SEO basics
robots, sitemap, OpenGraph, canonical
Server fingerprinting
Server header, version disclosure
Honeypot detection
Hidden form fields and trap endpoints

Here's what you'll get

A letter grade, a per-category breakdown, and any earned achievements.

RECENT FREE SCAN
A−
82 / 100
mozilla.org
A+
3 categories
A
12 categories
B
2 categories
Achievements earned
Hardened HeadersTLS ExcellenceNo Hidden Files

Need deeper analysis?

Free scan covers the surface. Pro tiers go all the way to the patch.

Free Security Scan — 135 checks · 30 seconds | patchguard · Patchguard