What an outsider can see about your site
We check what can be learned about your site without logging in: the certificate, headers, open paths and advertised versions. No access, no code, no contract.
HTTPS and certificate
Whether it is valid, when it expires, and whether the whole site redirects to the secure address.
Security headers
CSP, HSTS, X-Content-Type-Options and others. What each one buys, and which ones we do not demand.
What leaks outward
Open directories, leftover configuration files, advertised engine and module versions.
Forms and cookies
Whether forms submit securely and whether cookies carry Secure and HttpOnly.
What this check covers
The audit looks from a visitor's side — exactly as an outsider would. So it needs no server access, no FTP and no plugin: everything it sees is public and already available to anyone.
The first part is transport: whether the certificate is valid, whether it expires in a fortnight, whether http redirects to https. This is the most common and cheapest problem — and the only one a visitor notices unaided.
The second part is what a site says about itself for no reason: an engine version in a header, an open directory listing, a leftover config file. None is a vulnerability by itself, but together they are a map for anyone looking.
What you get out of it
The direct benefit is simple: an expired certificate closes a site to everyone, not slightly. It is a failure that arrives with a date, so the only way to avoid it is to know that date in advance.
The second benefit is indirect but real for search. HTTPS is a confirmed Google ranking signal, and sane headers plus fast TLS show up in Core Web Vitals. Security and visibility are not two separate jobs here.
secH2c
secP6
secP7
Guide
Answers to questions about SEO, GEO and AI visibility. Every article answers in its first paragraph, then shows how to check it on your own site.
Sources
What this page rests on — primary documents, not retellings:
What else we can check
SEO audit
A free scan with five scores and a list of what to fix first.
Read more →
GEO audit
Whether AI crawlers reach you and whether your text fits citation.
Read more →
Speed test
PageSpeed score, Core Web Vitals and the files making it slow.
Read more →
GEO optimization
Whether ChatGPT, Perplexity and Google AI see and cite your site.
Read more →
SEO services
Which SEO services you need, and which three you can skip paying for.
Read more →
Consultation
An hour with a person: what to fix first, hand over, or skip.
Read more →
Frequently asked questions
Does this replace a penetration test?
No, and saying otherwise would be dishonest. A pentest hunts for vulnerabilities from the inside and is done by a person. We check what is visible from outside with no access — the first layer, not the last.
Does the check break anything?
No. We send ordinary requests, the same as a browser, honour robots.txt and limit the rate. No attacks, no login attempts.
I have a critical finding — what first?
The certificate and the HTTPS redirect, then headers. The first two affect every visitor, and headers are configuration lines you can usually add in minutes.
Do you require every possible header?
No. COEP and Trusted Types matter only for sites with cross-origin isolation — demanding them from an ordinary site would be inventing a problem.
Start with what search and AI know about you today
The first scan is free and needs no account. The report stays available at its link.
Scan a domain →