What is checked
Only signals visible to anyone from outside are checked, such as certificate and connection settings, security headers and information left publicly exposed. The result lists strengths and areas to improve in plain language.
A limited preliminary assessment of externally visible security signals.
Certificate and connection settings
Use of basic security headers
Visible version and software signals
A limited preliminary assessment of externally visible security signals.
Share your website address and basic details.
Agree the authorized preliminary assessment scope.
Review strengths and areas for improvement.
Only signals visible to anyone from outside are checked, such as certificate and connection settings, security headers and information left publicly exposed. The result lists strengths and areas to improve in plain language.
No login attempts are made, no forms or sessions are attacked and no load is put on the site. The scorecard is not a penetration test; a detailed test is a separate service carried out with a written scope and permission.
Request a scorecard only for a site you own or are authorised to act for. This site does not currently run a real scan; the form shows the sample flow.
The result is a priority list. Your own team can make the fixes; if you prefer, we agree the scope in writing and take on the fixes and the re-check. Requesting the assessment does not commit you to buying any service.
The other security pages: scope, the reporting route and the emergency line.