Free · No results retained
Check your site's baseline security in seconds
SecureCheck runs a passive scan — like a regular browser visit — to spot the most common configuration flaws. No port scanning, no intrusion attempt.
Only use this tool on a site you own or are responsible for. SecureCheck only performs passive requests (identical to a browser visit): no port scanning, no intrusion attempt, no exploitation.
What SecureCheck checks
HTTP security headers
Detects missing headers that protect against clickjacking, MIME sniffing and referrer leaks.
Exposed files
Looks for sensitive files accidentally made public (.env, .git, backups, configuration files).
CORS misconfiguration
Checks that your API does not allow any third-party origin to read responses with the user's credentials.
Exposed API keys
Scans the page's public source code for keys or secrets accidentally committed client-side.
TLS certificate
Checks the validity, upcoming expiration and basic configuration of the HTTPS certificate.
How it works
1. Enter the URL
Provide the public address of a site you own or are responsible for.
2. Passive scan
SecureCheck only performs GET requests, exactly like a regular browser would.
3. Clear report
Each check is explained in plain language, with its severity if an issue is found.
Built for AI-assisted developers
Did you generate your site with the help of an AI and you're not sure about the security basics? SecureCheck freely checks the most common control points, no technical skill required and without ever touching your infrastructure.