Automated security scanning

Know your site's
security posture

Check HTTP security headers, SSL certificates, DMARC records, and exposed sensitive files. Get an actionable security grade in seconds — no login required.

What gets checked

HTTP security headers · SSL/TLS certificate validity · DMARC DNS record · Exposed .env and .git/config files

How grading works

Passing checks earn points toward 100. Critical failures trigger automatic F regardless of other results.

Responsible use

Only scan systems you own or are explicitly authorised to test. Passive observation only.

Built by

Christian Oguine · CEH Certified · Cybersecurity & Full-Stack Developer · Ghent, Belgium

What gets checked

Four categories of surface-level security checks run in parallel on every scan.

HTTP Security Headers

Checks for CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and technology disclosure headers.

SSL/TLS Certificate

Verifies the certificate is valid and checks how many days remain before expiry.

DMARC DNS Record

Checks for a DMARC record and evaluates the policy strength against email spoofing.

Exposed Sensitive Files

Attempts to access /.env and /.git/config — files that should never be publicly reachable.

More projects

Other things built by Christian Oguine.