SECURITY AUDIT

What an outsider can see about your site

We check what can be learned about your site without logging in: the certificate, headers, open paths and advertised versions. No access, no code, no contract.

01

HTTPS and certificate

Whether it is valid, when it expires, and whether the whole site redirects to the secure address.

02

Security headers

CSP, HSTS, X-Content-Type-Options and others. What each one buys, and which ones we do not demand.

03

What leaks outward

Open directories, leftover configuration files, advertised engine and module versions.

04

Forms and cookies

Whether forms submit securely and whether cookies carry Secure and HttpOnly.

What this check covers

The audit looks from a visitor's side — exactly as an outsider would. So it needs no server access, no FTP and no plugin: everything it sees is public and already available to anyone.

The first part is transport: whether the certificate is valid, whether it expires in a fortnight, whether http redirects to https. This is the most common and cheapest problem — and the only one a visitor notices unaided.

The second part is what a site says about itself for no reason: an engine version in a header, an open directory listing, a leftover config file. None is a vulnerability by itself, but together they are a map for anyone looking.

What you get out of it

The direct benefit is simple: an expired certificate closes a site to everyone, not slightly. It is a failure that arrives with a date, so the only way to avoid it is to know that date in advance.

The second benefit is indirect but real for search. HTTPS is a confirmed Google ranking signal, and sane headers plus fast TLS show up in Core Web Vitals. Security and visibility are not two separate jobs here.

secH2c

secP6

secP7

Guide

Answers to questions about SEO, GEO and AI visibility. Every article answers in its first paragraph, then shows how to check it on your own site.

Sources

What this page rests on — primary documents, not retellings:

Frequently asked questions

Does this replace a penetration test?

No, and saying otherwise would be dishonest. A pentest hunts for vulnerabilities from the inside and is done by a person. We check what is visible from outside with no access — the first layer, not the last.

Does the check break anything?

No. We send ordinary requests, the same as a browser, honour robots.txt and limit the rate. No attacks, no login attempts.

I have a critical finding — what first?

The certificate and the HTTPS redirect, then headers. The first two affect every visitor, and headers are configuration lines you can usually add in minutes.

Do you require every possible header?

No. COEP and Trusted Types matter only for sites with cross-origin isolation — demanding them from an ordinary site would be inventing a problem.

Start with what search and AI know about you today

The first scan is free and needs no account. The report stays available at its link.

Scan a domain →