Automated security scanning

Know your site's
security posture

Check HTTP security headers, SSL certificates, DMARC records, and exposed sensitive files. Get an actionable security grade in seconds — no login required.

3 scans per IP per hour · passive checks only · no exploitation or injection

What gets checked

HTTP security headers · SSL/TLS certificate validity · DMARC DNS record · Exposed .env and .git/config files

How grading works

Passing checks earn points toward a score of 100. Critical failures — exposed credentials or missing SSL — trigger automatic F regardless of other results.

Responsible use

Only scan systems you own or are explicitly authorised to test. Passive observation only — no exploitation, no injection.

Built by

Christian Oguine · CEH Certified · Cybersecurity & Full-Stack Developer · Ghent, Belgium

What gets checked

Four categories of surface-level security checks run in parallel on every scan.

HTTP Security Headers

Checks for CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and technology disclosure headers. Missing headers leave browsers unprotected.

SSL/TLS Certificate

Verifies the certificate is valid and checks how many days remain before expiry. A missing or expired certificate means all traffic travels unencrypted.

DMARC DNS Record

Checks for a DMARC record and evaluates the policy strength. Missing DMARC allows anyone to send emails appearing to come from your domain.

Exposed Sensitive Files

Attempts to access /.env and /.git/config — files that should never be publicly reachable. Exposure means credentials and source code are compromised.

More projects

Other things built by Christian Oguine.