Free. No card. No plugin.

Paste your link. Watch the weak spots appear, with how to close each one.

Nine checks run at once, read-only, on a site you have proven is yours. You get back only what we could prove, in plain words, with the exact change to make.

Free. No card. No plugin. Nothing on your site changes.

  • 9 checks

    Run at once, in one pass.

  • 0 guesses

    Not proven, not reported.

  • 0 changes

    Read-only. Your site is never modified.

  • Free

    No card, no time limit.

How it works

verify · example.comDemonstration
Demonstration of the flow. No real site, no real finding.
  1. 01

    Prove it is yours

    One DNS record or one file, once per site. It is also why nobody can point this scanner at your site but you.

  2. 02

    Nine checks run at once

    Security headers, TLS, cookies, SPF and DMARC, open redirects, and safe probes for XSS, SQL injection, access control and leaked keys. Read-only, on your domain only.

  3. 03

    You make the change, then scan again

    Each finding comes in plain words, with how we proved it and the exact change to make. Apply it, scan again, and watch it come back clean.

Features

Nine questions your site should be able to answer.

We ask them for you, and bring back each answer with what to change.

Can someone send email as you?

Without SPF and DMARC, nothing tells inboxes to reject mail forged in your name. We read both records and tell you exactly what to publish.

Check any domain now, no sign-in

SPF · DMARC

Is your padlock about to break?

An expired or mismatched certificate puts a full-page warning in front of every visitor. We check that HTTPS works and flag a certificate that expires within two weeks.

TLS · HTTPS

Are your browser defenses switched on?

Four response headers stop whole classes of attack before they start. We check each one and give you the exact line to add.

CSP · HSTS · X-Frame-Options · nosniff

Are your keys sitting in public code?

API keys shipped in your JavaScript can be read by anyone. We scan your scripts and show which key leaked, masked, so the report never spreads it.

JavaScript

Can one visitor open another person’s data?

We request neighboring records the way a visitor would, and report it only when a different owner’s data comes back.

IDOR · BOLA

Do your cookies guard the session?

A cookie without Secure, HttpOnly and SameSite can be read by a script or sent where it should not go. We check every cookie your home page sets, and never store its value.

Secure · HttpOnly · SameSite

Does your site echo code back?

If a parameter comes back unescaped, a single link can run script in your visitors’ browsers. We test with a harmless marker.

XSS

Does one quote mark break your database?

We add a single quote to your parameters and look for a database error in the reply. Nothing is changed, nothing is extracted.

SQLi

Can a link on your domain send people anywhere?

An open redirect lends your trusted address to phishing links. We try the usual redirect parameters with a harmless address.

?next= · ?url= · ?redirect=

Nobody can point this at a site they do not own. Including yours.

Every scan starts with proof: a file or a DNS record that only the owner can publish. No proof, not a single request. It is why you can trust the report, and why nobody can use us against you.

Questions

No. It only sends read-only requests to the domain you verified. Methods that change data are refused in the code itself, not by a setting.

It costs nothing to look.

Paste your link, prove it is yours, and in a few minutes you will know what is open and how to close it. If your site is clean, we will say so, plainly.