Website Safety & Security Checker
Free, no signup. A practical security snapshot from public signals — useful for prioritizing fixes, never a penetration test.
Checks run from our server; we fetch the URL you enter and don't keep the results. This fetches a public page and security.txt. The optional Google Web Risk component is a blocklist advisory, not a live malware scan. No certificate-expiry claim is made. Anonymous run-level outcome counters may be used for aggregate research; URLs, domains, IPs, and identifiers are never included, and no statistic is released below 100 runs.
Compare up to three URLs
Checks run sequentially and are not cached as a batch. Grades cover the same bounded public signals as the single check.
| URL | Grade | Score | Observed evidence |
|---|
Sample report
Illustrative example — deterministic complete public-signal fixture
Safety snapshot: 100/100
HTTP 200 · TLS handshake succeeded.
- Security headers: all scored header rules pass; COEP absence is informational only.
- Mixed content: no HTTP subresources or insecure form actions in the supplied HTML.
- security.txt: valid required fields found.
- Web Risk: not configured, so no malware/blocklist verdict is claimed.
This perfect fixture is intentionally narrow: it demonstrates scoring and is not described as a secure real-world website.
How to use it
- Enter the exact public URL and choose Run safety check.
- Read the overall letter as a summary of the implemented checks, then inspect the security-header grade and every reason.
- Distinguish a configured Web Risk advisory from checks marked not configured or not evaluated.
- Validate and prioritize changes with the site's security owner; do not use this report as a penetration-test substitute.
+ saves the current site or page. Use ☆ beside any saved site, page, or list to favorite it. Recent check history appears below.
Create a named list
Target filled from your local choices.
Site passport Local context for this saved site
Local data
Saved targets, named lists, and recent check summaries remain only in this browser.
Security headers
Public trust signals
Issues to review
This combines bounded public checks. It does not test authentication, application logic, vulnerabilities, malware behavior, certificate expiry, or every rendered resource.
Rate this tool
What the results mean
- A through F maps the numeric score into a summary band; it is not a risk certification.
- Security header grade comes from explicit pass, warning, error, and informational header rules.
- Issues to review lists every score reason plus security.txt and mixed-content evidence.
- Not configured or not evaluated is unavailable evidence, never a clean Web Risk verdict.
How it works
The endpoint fetches the public page, selected response headers, security.txt, limited RDAP data, and an optional Google Web Risk advisory. Shared deterministic functions scan bounded raw HTML for insecure subresources and form actions and validate required security.txt fields; the browser grades the returned evidence and combines those bounded signals into a documented score.
Features
- Security-header findings with exact remediation details.
- Raw-HTML mixed-content and insecure-form checks.
- security.txt validation and limited RDAP context.
- Optional Google Web Risk advisory with unavailable states preserved.
- Evidence-led score with explicit reasons.
- Sequential comparison of up to three public URLs.
Limitations
This is not a penetration test, vulnerability scan, certificate inspector, privacy audit, or live malware analysis. It does not execute JavaScript or inspect every rendered resource, application route, dependency, account control, server port, or security practice. A high score only describes the fetched public signals.
Frequently asked questions
Does an A grade mean a website is safe?
No. It means the bounded public checks scored well. The tool does not test application vulnerabilities, authentication, server configuration, malware behavior, social engineering, or data handling.
What does a Google Web Risk result mean?
When configured, it checks whether Google Web Risk returns a matching blocklist advisory. No match is not a live malware scan or a guarantee that a page is harmless.
Why does security.txt affect the score?
A valid security.txt gives researchers a standard way to report vulnerabilities. It is a useful public trust and response-readiness signal, but it does not make the application itself secure.
Can this checker see an expired certificate?
No. It records whether the HTTPS connection completed, but the Worker interface does not expose certificate expiry, hostname coverage, chain, or cipher details.
What is mixed content?
Mixed content occurs when an HTTPS page references an HTTP subresource or posts a form to HTTP. Those patterns can weaken transport protection and are detected only when visible in the fetched source.
Feature requests for Website Safety Checker
Upvote what you want most. New ideas can be submitted from the floating Feedback menu; requests appear here once approved, and the most-wanted rise to the top.
You won't be emailed about that request anymore.
Loading…
➕ Request a feature
New requests are reviewed before they appear here.
Tentang alat
Apa adalah mixed konten?
Ketika configured, ini memeriksa apakah Google Web Risiko mengembalikan mencocokkan blocklist advisory. Tidak ada cocok tidak langsung malware scan atau jaminan yang halaman adalah harmless.
Apa melakukan Google Web Risiko hasil mean?
Fitur
- Tidak. Ini berarti dibatasi publik memeriksa scored well. alat tidak uji aplikasi vulnerabilities, authentication, server konfigurasi, malware perilaku, social engineering, atau Penanganan data.
- Dapat ini pemeriksa melihat expired certificate?
- valid keamanan.TXT memberikan researchers standar way untuk laporan vulnerabilities. Ini adalah berguna publik trust dan respons-readiness sinyal, tetapi ini tidak buat aplikasi dirinya sendiri secure.
- Bagaimana untuk gunakan ini Masukkan tepat publik URL dan pilih Jalankan safety periksa. Baca overall letter sebagai summary dari diterapkan memeriksa, lalu periksa keamanan-header grade dan setiap alasan. Distinguish configured Web Risiko advisory dari memeriksa marked tidak configured atau tidak dievaluasi. Validasi dan prioritize perubahan dengan situs's keamanan pemilik; tidak gunakan ini laporan sebagai penetration-uji substitute.
- Melakukan grade mean situs web adalah aman?
Cara kerja
Keamanan header Publik trust sinyal Masalah untuk tinjau Ini combines dibatasi publik memeriksa. Ini tidak uji authentication, aplikasi logika, vulnerabilities, malware perilaku, certificate expiry, atau setiap dirender sumber daya. URL untuk periksa Jalankan safety periksa graded, bukti-led situs web safety snapshot: header, publik trust sinyal, insecure konten, keamanan.TXT, opsional Google Web Risiko, dan honest batasan. Fitur Keamanan-header temuan dengan tepat remediation details. Mentah-HTML mixed-konten dan insecure-form memeriksa. keamanan.TXT validasi dan limited RDAP konteks. Opsional Google Web Risiko advisory dengan tidak tersedia keadaan preserved. Bukti-led score dengan eksplisit alasan. Sequential comparison dari up untuk tiga publik URLs.
Batasan
- Bagaimana ini berfungsi endpoint mengambil publik halaman, dipilih header respons, keamanan.TXT, limited RDAP data, dan opsional Google Web Risiko advisory. Bersama deterministik functions scan dibatasi mentah HTML untuk insecure subresources dan form tindakan dan validasi wajib keamanan.TXT fields; browser grades dikembalikan bukti dan combines itu dibatasi sinyal menjadi terdokumentasi score.
- Mengapa melakukan keamanan.TXT affect score?
- Tidak. Ini catatan apakah HTTPS connection completed, tetapi Worker interface tidak mengekspos certificate expiry, hostname cakupan, rantai, atau cipher details.
- Bandingkan up untuk tiga URLs Satu publik URL per baris Bandingkan safety sinyal Memeriksa jalankan sequentially dan tidak disimpan di cache sebagai batch. Grades cover sama dibatasi publik sinyal sebagai single periksa. URL Grade Score Teramati bukti
Pertanyaan umum
Bandingkan up untuk tiga URLs Satu publik URL per baris Bandingkan safety sinyal Memeriksa jalankan sequentially dan tidak disimpan di cache sebagai batch. Grades cover sama dibatasi publik sinyal sebagai single periksa. URL Grade Score Teramati bukti
Keamanan header Publik trust sinyal Masalah untuk tinjau Ini combines dibatasi publik memeriksa. Ini tidak uji authentication, aplikasi logika, vulnerabilities, malware perilaku, certificate expiry, atau setiap dirender sumber daya.
URL untuk periksa Jalankan safety periksa
graded, bukti-led situs web safety snapshot: header, publik trust sinyal, insecure konten, keamanan.TXT, opsional Google Web Risiko, dan honest batasan.
Fitur Keamanan-header temuan dengan tepat remediation details. Mentah-HTML mixed-konten dan insecure-form memeriksa. keamanan.TXT validasi dan limited RDAP konteks. Opsional Google Web Risiko advisory dengan tidak tersedia keadaan preserved. Bukti-led score dengan eksplisit alasan. Sequential comparison dari up untuk tiga publik URLs.
Batasan Ini tidak penetration uji, vulnerability scan, certificate inspector, privasi audit, atau langsung malware analysis. Ini tidak execute JavaScript atau periksa setiap dirender sumber daya, aplikasi rute, dependency, akun kontrol, server port, atau keamanan latih. tinggi score hanya menjelaskan diambil publik sinyal.
Mixed konten occurs ketika HTTPS halaman references HTTP subresource atau posts form untuk HTTP. Itu pola dapat weaken transport protection dan adalah detected hanya ketika terlihat di diambil sumber.
Gratis, tanpa pendaftaran. practical keamanan snapshot dari publik sinyal — berguna untuk prioritizing perbaikan, tidak pernah penetration uji.