[ Website security audit ]

Is your website
actually secure?

Run a free, honest security audit. Every check is mapped to a real standard - OWASP and Mozilla, not made-up scores. See exactly what's broken and how to fix it.

We only make public requests to your site. No signup to run it.

[ The problem ]

Most sites fail
the security basics.

01 / Headers

Missing security headers

HSTS, CSP, frame protection: the headers that shut down whole attack classes are simply absent on most sites.

02 / Files

Files left in public

.env files, wp-config backups and readme files hand credentials and version info to anyone who asks.

03 / Disclosure

Oversharing servers

X-Powered-By headers and generator tags tell attackers exactly which exploits to try first.

04 / Noise

Scanners that shout

Most audit tools bury you in jargon and red alerts to sell a plan. You still don't know what to fix first.

[ How it works ]

Scan. See. Fix.

01

Scan free

Enter your domain. We run 15 checks using only public requests, looking at your site the same way an attacker would. No signup, no agent to install.

02

See what's broken

You get a plain-English report: what failed, why it matters, and the exact OWASP or Mozilla guideline behind it. Unlock the full report with your email.

03

Fix it

Pro turns findings into fixes: step-by-step guidance, ready-to-paste WordPress snippets, and one-click Cloudflare applies with undo. Re-scan and watch the score climb.

[ The report ]

An honest report card.

One score, a clear grade, and every finding explained in plain English: what it is, why it matters, and the standard it comes from. Pass, warn or fail. No padding, no invented severity.

See your own report
example.com 64/100 · grade C
Strict-Transport-Securitypass
X-Content-Type-Optionspass
Content-Security-Policywarn
X-Frame-Optionsfail
.env exposurepass
xmlrpc.php enabledfail

Sample. 6 of 15 checks shown. Every finding links to the standard behind it.

[ What we check ]

15 checks. Zero fluff.

HSTSStrict-Transport-SecurityMozilla
CSPContent-Security-PolicyOWASP
XFOX-Frame-OptionsOWASP
XCTOX-Content-Type-OptionsMozilla
REFReferrer-PolicyMozilla
PERMPermissions-PolicyMozilla
HTTPSForced HTTPS redirectMozilla
TLSTLS protocol + certificateOWASP
CKIECookie security flagsOWASP
XMLRPCxmlrpc.php exposureWordPress
ENUMUser enumerationWordPress
ENV.env file exposureOWASP
WPCFGwp-config backupsWordPress
DISCVersion disclosureOWASP
RDMEreadme.html exposureWordPress

[ The difference ]

No fear-mongering. Ever.

Security tools love red alerts. We don't. If we can't point at the public guideline a finding comes from, we don't flag it.

Mapped to real standards

Every finding cites the OWASP or Mozilla guideline behind it, with a link. You can verify everything we say.

Honest severity

Plain English: what it is, why it matters, how urgent it really is. This is a technical posture report, not a compliance certificate, and we say so.

We will never auto-apply CSP.

A wrong Content-Security-Policy can take down your checkout or your page builder. Some fixes deserve a human, so CSP gets guided, report-only rollout instead. Even on Pro.

[ Checks ]

15

public-request checks per scan

[ Signup ]

0

accounts needed to run a scan

[ Standards ]

100%

of findings mapped to a source

[ Pro fixes ]

1-click

Cloudflare applies, always undoable

[ Pricing ]

Free to scan.
Pro to fix.

Free

Free

See exactly where you stand.

  • Full 15-check scan
  • Plain-English report: what failed and why
  • Standard link on every finding
  • Remediation task list for 1 site
  • Re-scan anytime
Run a free audit

Pro Launching soon

€29/month

Turn every finding into a fix.

  • Everything in Free
  • Step-by-step fix guidance per finding
  • Ready-to-paste WordPress snippets
  • One-click Cloudflare fixes, with undo
  • Auto re-scan after every fix
  • Up to 25 sites
Start with a free audit

Pro launches soon. The scan stays free.

[ FAQ ]

Frequently asked questions.

Is the scan safe to run on my site?

Yes. We only make normal, public HTTP requests, the same kind any browser or search engine makes. Nothing invasive, no exploitation, no load testing.

Do I need an account?

No. The scan runs without any signup. You unlock the full report with your email address, and that's all we ask for.

What exactly do you check?

15 checks across security headers, TLS and HTTPS configuration, cookie flags, exposed files, and WordPress-specific issues like xmlrpc.php and user enumeration. Every check is mapped to an OWASP or Mozilla guideline.

What does Pro add?

Fixes. For every finding, Pro shows step-by-step guidance, ready-to-paste WordPress snippets, and where your site runs behind Cloudflare, one-click applies with undo. After each fix we re-scan automatically so you see the score move.

How do the one-click Cloudflare fixes work?

You connect a narrowly-scoped Cloudflare API token. For fixable findings we create tagged rules in your zone: security headers, WAF blocks for exposed paths, HTTPS settings. Every change is recorded and can be undone with one click. We never touch anything else in your account.

Is this a compliance certificate?

No. This is a technical posture report: an honest picture of your site's security basics. It is not a penetration test and it does not certify compliance with any regulation.

[ Ready when you are ]

Know what's broken.
Tonight.

One scan, 15 checks, zero signup.

We only make public requests to your site.