Free Website Security Checker

Scan a site’s security posture in seconds — HTTPS/TLS, security headers, CSP quality, HSTS, cookie flags, mixed content, Subresource Integrity, SPF/DMARC email spoofing and common exposures — and get an A–F grade with prioritised fixes. A passive assessment you can run on your own site, free.

This is a passive posture check of what your site openly serves — not a penetration test. Scan sites you own or have permission to test.

How your security grade is scored

The A–F grade and 0–100 score reflect what your server openly reveals, weighted by impact. Findings are ranked critical, warning or notice: a missing HTTPS redirect or a publicly readable .git directory drags the grade down hard, while an absent Permissions-Policy header is a lighter notice. Read the grade as a triage signal, not a pass/fail — a B with two warnings usually means a handful of headers to add, not a rebuild. The letter uses the same scale as the full audit report, so the same score earns the same grade everywhere on the site.

Which gaps to fix first

Work top-down by severity. In practice the highest-leverage fixes are almost always:

  • Force HTTPS and add HSTS — redirect every HTTP request and set Strict-Transport-Security so browsers refuse the insecure version.
  • Ship a real Content-Security-Policy — the single strongest defence against injected scripts, and the one most sites leave off.
  • Harden cookies — every cookie should carry Secure, HttpOnly and a SameSite flag.
  • Close exposures — a reachable .env or .git path leaks credentials and source; block it immediately.

The email-spoofing check most scanners skip

The scan also reads your DNS for SPF and DMARC records. Without them, anyone can send mail from your domain — a favourite of phishing campaigns that damages both deliverability and brand trust. A published SPF record plus a DMARC policy set to at least quarantine tells receiving servers which senders are legitimate, and this is easy to miss because it lives in DNS, not on the page.

Frequently asked questions

What does the Website Security Checker test?

It runs a passive assessment of what your site openly serves: whether it’s on HTTPS, the TLS version + certificate validity, and whether deprecated TLS 1.0/1.1 are still enabled; whether HTTP redirects to HTTPS and if HSTS is preload-eligible; the six key security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) plus Content-Security-Policy quality; cookie security flags (Secure, HttpOnly, SameSite); mixed content and Subresource Integrity on third-party scripts; email spoofing protection (SPF and DMARC via DNS); CAA certificate-issuance control and DNSSEC; software version disclosure; a security.txt contact; and well-known misconfigurations like a publicly readable .git or .env. You get an A–F grade and a prioritised list of fixes.

Is this a penetration test (VAPT/WAPT)?

No — and it’s important to be clear about that. This is an automated, passive security posture check: it only reads what your server already returns and looks for common misconfigurations. A real penetration test actively probes for exploitable vulnerabilities and is a manual, authorised engagement by a security professional. Use this tool as a fast first pass and to fix the obvious gaps; commission a proper pentest for anything handling sensitive data.

Can I scan any website?

Only scan sites you own or are explicitly authorised to test. The checks here are non-intrusive (they read public responses and a couple of well-known paths), but you should still have permission. The tool is rate-limited to keep it light on the target.

Why do security headers matter for SEO too?

Beyond protecting visitors, HTTPS and a solid security posture are trust and quality signals. Browsers warn users away from insecure sites, and a hacked or warning-flagged site loses rankings and clicks fast. Fixing these protects both your users and your search performance.

Embed this free tool on your site

Add this website security checker to your own blog or website — it stays free for your visitors, and the short credit line links back here. Just copy the snippet and paste it into your page’s HTML.

Embed code (HTML)
<iframe src="https://seoaiaudits.com/embed/security-checker" width="100%" height="700" style="border:1px solid #e5e7eb;border-radius:12px;max-width:760px;width:100%" loading="lazy" title="Website Security Checker"></iframe>
<p style="font-size:13px;font-family:system-ui,sans-serif;margin-top:8px;color:#6b7280">
  Free <a href="https://seoaiaudits.com/tools/security-checker" target="_blank" rel="noopener">Website Security Checker</a> by <a href="https://seoaiaudits.com" target="_blank" rel="noopener">SEO AI Audits</a>
</p>

Tip: adjust height if your layout needs more or less room. Please keep the credit line so others can find the tool.

Want a different one? See every tool you can embed.

Related free tools

Want the full picture?

This tool checks one thing. Run a complete, free SEO audit across 28 modules.

Run a free SEO audit