Run the free check: 19 tests on what is visible from the outside. No account, no login, no waiting.

How secure is your website, really?

Read-only: we look at connection settings, HTTP headers and public DNS records. We never log in, never submit anything and never probe for files. Only check sites you own or manage.

What this check does

Most of the security problems we run into on websites are not spectacular. They are settings that simply are not there: a site that is still reachable over plain http next to https, a cookie without a Secure flag, a header that should have told the browser what it may and may not load. They are visible from the outside, they are fixed in an afternoon, and they sit there for years because nobody looks.

This tool looks. You enter your web address, we make the same requests any visitor makes, and within a minute you get a grade with, underneath it, what each check found, why it matters and what to do about it.

What we check

  • Connection: does http redirect to https, is the certificate valid and renewed in time, and which TLS versions are still open.
  • HSTS: does the site tell browsers to come back over https only from now on.
  • Content-Security-Policy: is there a policy governing which scripts and resources may load: the main brake on code that hitches a ride.
  • Clickjacking: can your site be placed in a frame on someone else’s site.
  • Referrer and Permissions-Policy: what leaks along to other sites, and which device permissions (camera, microphone, location) are left open.
  • nosniff: may the browser guess for itself what kind of file it is receiving.
  • Cookies: do Secure, HttpOnly and SameSite appear on the cookies the site sets itself.
  • Versions in headers: does the server announce which software and which version is running underneath.
  • security.txt: can someone who finds a problem actually reach you.
  • Email and DNS: SPF, DMARC and CAA, that is, whether somebody else can send mail in your domain’s name or request a certificate for it.

Nineteen checks in total. The grade runs from A to F: A from 90 points, B from 75, C from 60, D from 40. A low letter is not a disaster and an A is not a guarantee. See the questions at the bottom.

What we do not do

This is emphatically not a penetration test and not an attack. Everything the tool does is request and look up:

  • We never log in and we do not try passwords.
  • We do not submit forms and we do not create any entries.
  • We do not hunt for files or hidden folders, and we do not try to exploit anything.
  • We do not put load on your site: it comes down to a handful of ordinary page requests, and each visitor gets at most six checks per quarter of an hour.

That is a deliberate choice. A tool you offer to strangers has to be something you would run against your own site without hesitating.

For Umbraco sites we look one step further

If Umbraco is running underneath, the check picks that up and tests two more things: whether the backoffice is open to the whole internet, and which versions the site gives away by itself. That last one surprises most people. The login page of a modern Umbraco loads its own parts through a list of file names, and those names carry version numbers, of Umbraco itself and of the installed packages. You do not have to log in to see which versions are running. On our own site that yields the names and numbers of two packages.

That is not a leak in itself. It becomes one the moment a security update for such a version is published and you have not updated yet: your login page then tells the world you are vulnerable. Which is why, for the sites we manage, we track versions ourselves and roll security updates across the fleet. See how long your Umbraco version will be supported.

The report

Right after the check the result is on this page. If you want to keep it or forward it to whoever maintains the site, fill in the form below: you get the report by email with a link of its own. That link keeps working for 30 days and is gone afterwards: a snapshot from months ago says nothing about a site any more. Report pages are not in Google and not in our sitemap.

Frequently asked questions about the security check

Nothing, and you do not need an account. You enter a web address and the result appears on screen. If you want it by email, we only ask for your name and email address.

No. The tool only makes read requests (the same kind a visitor or a search engine makes) plus a few DNS lookups. Nothing is logged into, submitted, created or changed. In your logs you will see a handful of ordinary page visits.

Only check sites you own or manage. The check itself is harmless, but a report on the weak spots of someone else’s site is not yours to request. We keep track of how often a single address runs scans and limit that to six checks per quarter of an hour.

No, and that matters. This check measures what is visible from the outside: connection, headers, cookies, DNS. It does not look at your code, your database or who can log in. A site with an A can still run an outdated package or have an administrator account without two-factor authentication. Think of it as the outside of the house: closed windows tell you something, but not everything.

We keep the report behind its own link for 30 days, so the email you receive keeps working; after that it disappears. We use your email address to send you that report and, if you choose so, to get in touch. We do not sell anything on and we will not add you to a list you did not ask for.

No. Most of the checks are about connection, headers, cookies and DNS and apply to any website, whatever runs underneath. If we recognise Umbraco, two Umbraco-specific checks are added.

Every finding in the report comes with a "what to do" line. Most of them are a setting your administrator can apply in an afternoon. If you get stuck, or you want to know which points are a real risk in your situation and which are not: fill in the form and tick the box saying you would like to go through the report. Raoul de Vries will take a look with you.

Contactgegevens

Adres

The report in your inbox

Postbus

Fill in your details and this report arrives by email, with a link you can forward to whoever maintains the site.

 

Want to go through it together? Tick the box in the form and Raoul de Vries will take a look with you. In half an hour he walks through what each finding means in your situation. There is no quote waiting behind it; if nothing is wrong, we are just as happy to say so.

 

Prefer direct contact? Call or email us.

This is where we send the report.
Raoul de Vries (1)

Go through your Umbraco security together

The check looks at the outside. What sits behind it (which version you run, which packages still need updating, who can log in and how) comes out in half an hour with Raoul de Vries, one of our Umbraco engineers. No obligation, and concrete: you will hear what matters and what does not.