How the free scan works

Our scanner performs a lightweight, non-intrusive external check of your website — the same information any visitor's browser can see, with no login and no attempt to access anything private. It evaluates:

  • Encryption — whether your site loads securely over HTTPS.
  • Security headers — HSTS, Content-Security-Policy, X-Frame-Options, and more.
  • Software exposure — whether your server reveals version details attackers can use.
  • Exposed files — common sensitive files that should never be public.
  • Platform detection — the CMS or framework your site runs on.
  • Visible compromise signals — defacement text or known malicious script patterns on your homepage.

These findings are scored into a clear A–F grade. A scan is a starting point, not a full audit — a complete security assessment checks far more, including things only visible with proper access.

How we research and write

Our guides are drafted, then reviewed for technical accuracy before publishing. We prioritise correctness over speed: for recovery and removal guidance especially, a wrong instruction can make things worse, so we hold that content to a higher bar. We update guidance as platforms and threats change.

What we don't do

We don't exploit, break into, or test sites without permission. We don't publish attack instructions. Our focus is defensive: helping owners protect and recover their own sites.