Website security scan
See your site the way an attacker does.
Most break-ins start with something left in plain sight: a forgotten backup, an old plugin, a missing protection. We look from outside — nothing is broken into — and grade what we find.
- Non-intrusive: nothing is broken into
- A grade and what to fix first
- A technical audit for your developer
AGrade
2 to tidy · 0 to fixWhat an attacker sees from outside. Nothing is broken into.
- Encryption: TLS 1.3, certificate valid 71 days
- Browser protections (HSTS, framing)
- No exposed .git, .env or backups
- WordPress 6.4 — an update is due
- Login over HTTPS, no password hints
What the scan looks at.
Encryption
- TLS versions and ciphers
- Certificate and when it runs out
- HTTPS everywhere, with HSTS
Browser protections
- Content Security Policy
- Framing and sniffing protections
- Cookie settings
Exposed files
- .git and .env files
- Backups and database dumps
- Logs and directory listings
Software
- CMS and plugin versions
- Server software past its updates
- What the site gives away
The login
- Login over HTTPS
- Username hints
- Forms sent safely
Leaks & third parties
- Off-site scripts pinned (SRI)
- No mixed http content on secure pages
- Email addresses and comments left in the source
Two reports: one for you, one for your developer.
The security report gives you the grade, what to fix first and why it matters. The technical audit gives your developer every check with its evidence, mapped to CWE and the OWASP Top 10, and a command to confirm each fix.
A backup of the site is downloadable
$ curl -I https://yourbusiness.ca/backup.zipNo Content-Security-Policy header
$ curl -sI https://yourbusiness.ca | grep -i content-securityThe server names its software version
$ curl -sI https://yourbusiness.ca | grep -i serverQuestions, answered
Is the scan safe for my site?
Yes. It makes ordinary requests, like a visitor would — about sixty of them. It never tries passwords, never sends attacks and never changes anything.
Is this a penetration test?
No. A penetration test actively tries to break in, with your permission. Our scan finds what’s visible from outside, which is where most attacks begin, and it’s a good first step before a full test.
My site is on WordPress. Does that matter?
WordPress is safe when it’s kept up to date. The scan tells you if the version or the plugins it can see are behind.
Get a free security scan.
Tell us your website and we’ll send a free report: what’s working, what isn’t, and what to fix first. Or just call — we’re happy to talk it through.