What can anyone see about your site’s security?
Paste your address. We look at exactly what a visitor’s browser can see from outside — your certificate, your redirects, your headers, your public email records — and tell you, in plain words, what’s worth fixing first.
Passive on purpose
Anyone can paste any address into this box, including one they don’t own. So the tool only ever does what a browser already does: it asks for your homepage, looks at the certificate that comes back, follows the redirect, reads the headers, and looks up the DNS records that are public by design. It never asks for a hidden file, never scans a port, never touches a login form and never sends a test payload. Some of those would find more. All of them would make this a reconnaissance tool pointed at strangers, and we will not ship that.
What it checks
- Your padlock. Whether the certificate is trusted, current and issued for this exact address — the one security problem your customers see for themselves.
- http → https. Whether someone typing your domain plainly still lands on the encrypted version, with no insecure step on the way.
- Exposed keys. Whether a password-equivalent key is sitting in your page source where View Source shows it to everyone.
- Insecure form destinations. Whether a sign-in or payment box sends what people type over an unencrypted connection.
- Email spoofing. Whether a stranger can send email that looks like it came from your address — the standard setup for invoice fraud against your customers.
- Cookies and headers. Protective flags, HSTS, clickjacking protection, and the browser hardening headers, grouped so you aren’t buried in red.
Three answers, not two
Every item comes back as looks right, worth fixing, or couldn’t check. That third one matters more than it sounds. If a bot-protection screen answers instead of your site, or a lookup times out, we say so — we do not quietly count it as a pass. Turning “we couldn’t see it” into “you’re fine” is the most common way a free security tool misleads the person using it.
A site worth securing is a site worth showing
Once the basics are right, the next problem is the one every founder has: getting people to look at all. PromoHyper turns your URL into a fully designed promo video — script, voiceover, music, every frame built around your brand.
While you’re here — the other free tools
All of them work the same way: paste the same URL, get a different answer. No account.
Questions
- Is this a penetration test or a vulnerability scan?
- No, and we are careful about the difference. This is a passive check: we request your homepage the way any browser would, look at your certificate, and read your public DNS records. We never probe hidden files, scan ports, test logins or send any payload. A real assessment goes far deeper and needs the owner's permission and an agreed scope.
- Can I check a site I don't own?
- You can, and that is exactly why the tool is built this way. Everything it does is something your browser already does when it loads a page, so nothing here is intrusive no matter whose address you paste. It is also why we will not add hidden-file probing or port scanning, however useful they would be.
- Does a clean result mean my site is secure?
- No. It means the parts we could see from outside looked right at that moment. Your admin area, database, backups, dependencies and everyone's passwords are all invisible to us, and that is where most real break-ins start. A site is only as secure as its weakest link, and the weakest link is usually one nobody was looking at.
- What does "couldn't check" mean?
- It means we genuinely could not measure that item — a timeout, a bot-protection screen, or a DNS lookup that failed. We list those separately instead of counting them as passes. Turning "we couldn't see it" into "you're fine" is the most common way a free security tool misleads people.
- Is it free?
- Yes, three checks a day, no account. Need more in a day? Pay what you want for a 24-hour pass that works across all our tools.