Practical guides on web security — headers, SSL, and vulnerability checks — from the team behind a 40-check passive security scanner.
Test whether your website sends a Content-Security-Policy header, identify missing protections, and get practical CSP fixes with a free passive scan.
Check whether your website sends a valid Strict-Transport-Security header and learn how max-age, includeSubDomains, and preload affect HTTPS security.
Test for wildcard and reflected-origin CORS behavior, understand credential risks, and find unsafe cross-origin response configurations.
Check cookies for missing Secure, HttpOnly, and SameSite attributes and understand what each browser cookie protection prevents.
Test whether your website can be framed by another origin and check X-Frame-Options plus CSP frame-ancestors protections.
HSTS, CSP, X-Frame-Options, Referrer-Policy — what each header does, how to set it, and how to verify it's working. Includes a free instant checker.
SSL errors scare users and hurt SEO. Here's how to verify your certificate, understand expiry dates, and fix the most common TLS misconfigurations.
A practical security checklist covering headers, SSL, cookie flags, information exposure, and CORS misconfigurations. Run the free scanner to check yours in seconds.