Website security checker
Check your SSL certificate, HTTPS redirects and security headers in one report. See what needs attention, the evidence behind each finding, and what to fix first.
free · no sign-up · public websites on ports 80 and 443
enter a website to read its public security configuration
What your report covers
| check | what we look for |
|---|---|
| SSL certificate | Expiry, validity dates and hostname coverage for the host you enter. A separate HTTPS request checks whether our client accepts the certificate chain. |
| HTTPS and redirects | Whether HTTPS responds, HTTP redirects to HTTPS, and either observed chain returns to unencrypted HTTP. |
| HSTS | Whether the final HTTPS response tells browsers to remember HTTPS, and for how long. |
| Content Security Policy | Whether an enforced policy is present and whether common script restrictions need review. This is a basic policy review, not a complete CSP audit. |
| Framing protection | Whether CSP frame-ancestors or X-Frame-Options restricts which sites can embed the page. |
| Content type and referrer | Whether nosniff is configured and an explicit referrer policy limits URL details sent to other sites. |
Results describe the responses received from one probe location at the time of the check. A missing header is a configuration finding, not proof of an exploitable vulnerability. An error page or bot challenge can have different headers from your application.
Start with the findings that affect access
Fix expired certificates, hostname mismatches and HTTPS downgrades first. Then review header warnings against how your application works. Test policy changes before applying them to production: a restrictive CSP can block scripts your page needs, and framing restrictions can prevent intentional embedding.
The report places failures first, followed by warnings, incomplete checks and passes. Every pass applies to one stated check. This tool does not scan for malware or application vulnerabilities, inspect logged-in sessions, detect mixed content, or certify that a website is safe.
For the individual evidence, use the SSL certificate checker or HTTP header and redirect checker. Follow the certificate monitoring guide to get expiry alerts.
Header behavior references: MDN on HSTS, Content Security Policy, and Referrer-Policy.
Questions about the security check
What does this website security checker test?
Does a passing report mean my website is secure?
Why are some checks marked not checked?
Which page do the security headers describe?
Why do you check HTTP as well as HTTPS?
Can I monitor these results automatically?
Keep watching uptime and certificate expiry
This report is a snapshot. Set up monitoring to know when your site stops responding or its certificate approaches expiry.
Start monitoring freemore free tools: uptime SLA calculator · cron expression generator · error budget calculator · incident message generator · DNS lookup · HTTP header checker · SSL certificate checker · domain expiry checker · the whole set