Security scan

See exactly what's exposed — before someone else does

Read-only public-surface scan: HTTPS/redirects, security headers (HSTS/CSP/X-Frame-Options/nosniff/Referrer-Policy/Permissions-Policy), cookie flags, mixed content, WordPress exposure signals, forms/injection-surface inventory. Never attacks, logs in, or submits.

Read-only firstProof before doneRollback includedNo fake claims

What it does

Read-only public-surface scan: HTTPS/redirects, security headers (HSTS/CSP/X-Frame-Options/nosniff/Referrer-Policy/Permissions-Policy), cookie flags, mixed content, WordPress exposure signals, forms/injection-surface inventory. Never attacks, logs in, or submits.

What you get

A labeled before-report (PASS/MISSING/NOT_PROVEN/HELD) + a fix plan; most sites are missing basic headers and one safe server change fixes the lot.

Why it is safe

Read-only, public surface only — no exploits, no payloads, no login, no changes.

Frequently asked questions

Is the security scan safe to run on my site?
Yes — it's read-only and public-surface only (headers, public HTML, robots, sitemap, visible forms). It never logs in, submits, attacks, or changes anything.
What does the scan check?
Security headers, HTTPS/SSL setup, exposed files, mixed content, and visible form safety — then a 0–100 scorecard with a prioritized fix list.
Will fixing these break my site?
No. Every fix is drafted first and applied through an approved, reversible work order — you get before/after proof and can roll back anytime.