Free Website Security Scanner - Scan any website for security gaps in 30 seconds, free

A free website security scanner that works on any site, any platform. Enter your URL and get an instant 0-100 score plus plain-English findings: SSL/TLS health, security headers, cookie flags, exposed files (.env, .git, backups), SPF/DMARC email protection, and WordPress-specific exposure. Every check is passive and read-only, nothing is exploited. A full PDF report with fixes is emailed to you.

Add a comment

Replies

Best
Hey Product Hunt 👋 We're Tech Contributors, a small web development agency based in Delhi. We built this scanner because we kept finding the same avoidable problems when we took over client sites: missing security headers, exposed .env and backup files, expired or misconfigured SSL, and domains with no SPF or DMARC record, so anyone could spoof their email. Most existing tools check one slice (SSL only, or headers only). We wanted one plain-English report a non-technical business owner can actually act on. What it checks: - SSL/TLS certificate health and HTTPS redirect - Security headers, including the contents of your CSP - Cookie flags (Secure, HttpOnly, SameSite) - Exposed sensitive files and directory listings - SPF / DMARC email protection - WordPress-specific issues (XML-RPC, user enumeration, readme.html), only if WordPress is detected A few things worth knowing: - Every check is passive and read-only, the same requests a browser makes. We never send exploit payloads or try to break in. - You see your score and findings on the page instantly. The full PDF report with fixes is emailed to you, so the form asks for your name, email and phone. - It's free. If a report turns up something serious, our team is happy to help fix it, but there's no obligation. We'd love your feedback, especially on false positives, checks you wish it had, and anything in the report that's confusing. We read every comment. 🙏