[ Website security audit ]
Run a free, honest security audit. Every check is mapped to a real standard - OWASP and Mozilla, not made-up scores. See exactly what's broken and how to fix it.
We only make public requests to your site. No signup to run it.
[ The problem ]
01 / Headers
HSTS, CSP, frame protection: the headers that shut down whole attack classes are simply absent on most sites.
02 / Files
.env files, wp-config backups and readme files hand credentials and version info to anyone who asks.
03 / Disclosure
X-Powered-By headers and generator tags tell attackers exactly which exploits to try first.
04 / Noise
Most audit tools bury you in jargon and red alerts to sell a plan. You still don't know what to fix first.
[ How it works ]
Enter your domain. We run 15 checks using only public requests, looking at your site the same way an attacker would. No signup, no agent to install.
You get a plain-English report: what failed, why it matters, and the exact OWASP or Mozilla guideline behind it. Unlock the full report with your email.
Pro turns findings into fixes: step-by-step guidance, ready-to-paste WordPress snippets, and one-click Cloudflare applies with undo. Re-scan and watch the score climb.
[ The report ]
One score, a clear grade, and every finding explained in plain English: what it is, why it matters, and the standard it comes from. Pass, warn or fail. No padding, no invented severity.
See your own reportSample. 6 of 15 checks shown. Every finding links to the standard behind it.
[ What we check ]
[ The difference ]
Security tools love red alerts. We don't. If we can't point at the public guideline a finding comes from, we don't flag it.
Every finding cites the OWASP or Mozilla guideline behind it, with a link. You can verify everything we say.
Plain English: what it is, why it matters, how urgent it really is. This is a technical posture report, not a compliance certificate, and we say so.
A wrong Content-Security-Policy can take down your checkout or your page builder. Some fixes deserve a human, so CSP gets guided, report-only rollout instead. Even on Pro.
[ Checks ]
15
public-request checks per scan
[ Signup ]
0
accounts needed to run a scan
[ Standards ]
100%
of findings mapped to a source
[ Pro fixes ]
1-click
Cloudflare applies, always undoable
[ Pricing ]
Free
Free
See exactly where you stand.
Pro Launching soon
€29/month
Turn every finding into a fix.
Pro launches soon. The scan stays free.
[ FAQ ]
Yes. We only make normal, public HTTP requests, the same kind any browser or search engine makes. Nothing invasive, no exploitation, no load testing.
No. The scan runs without any signup. You unlock the full report with your email address, and that's all we ask for.
15 checks across security headers, TLS and HTTPS configuration, cookie flags, exposed files, and WordPress-specific issues like xmlrpc.php and user enumeration. Every check is mapped to an OWASP or Mozilla guideline.
Fixes. For every finding, Pro shows step-by-step guidance, ready-to-paste WordPress snippets, and where your site runs behind Cloudflare, one-click applies with undo. After each fix we re-scan automatically so you see the score move.
You connect a narrowly-scoped Cloudflare API token. For fixable findings we create tagged rules in your zone: security headers, WAF blocks for exposed paths, HTTPS settings. Every change is recorded and can be undone with one click. We never touch anything else in your account.
No. This is a technical posture report: an honest picture of your site's security basics. It is not a penetration test and it does not certify compliance with any regulation.
[ Ready when you are ]
One scan, 15 checks, zero signup.
We only make public requests to your site.