SSL & TLS configuration
See which protocols and cipher suites your server accepts, from legacy SSL to TLS 1.3. Identify outdated options and configuration-based weakness indicators.
Free website security checker
A clearer picture of your website’s security configuration. Check SSL/TLS, certificates and HTTP headers. Know what’s working. See what needs attention.
Separate grades. A more useful perspective.
01 / The checks
Move from an unexplained score to specific observations. Each layer gives you another part of the picture.
See which protocols and cipher suites your server accepts, from legacy SSL to TLS 1.3. Identify outdated options and configuration-based weakness indicators.
Inspect the certificate chain, browser trust, hostname match and expiration. Look into OCSP stapling and certificate transparency observations.
Check HSTS, Content-Security-Policy and other browser protections. Get a dedicated headers grade with the observations behind it.
Review security.txt and robots.txt, plus SPF and DMARC policies where available. These add context without changing your TLS or headers grades.
02 / From scan to understanding
Built for developers, site owners and anyone responsible for a website’s configuration.
Illustrative workflow
Enter your hostname. WebSec0 makes TLS connections, HTTP requests and DNS queries to inspect its configuration.
Review separate TLS and headers grades. Go deeper with certificate details, header values and clearly marked incomplete checks.
Use findings and the remediation catalog to plan your fixes. Run another check after updating your configuration.
A configuration check is one part of security. It does not replace an application security assessment.
Community activity
Open by design
Use the JSON API, inspect the checks or run your own instance. The same transparent engine, wherever you need it.
A few useful answers
WebSec0 checks a hostname’s TLS protocols, cipher suites, certificate chain and HTTP security headers. It also reports security.txt, robots.txt and, where available, SPF and DMARC DNS policies. TLS and HTTP headers receive separate grades; the other observations are informational.
Enter your domain above and run a scan. The report shows the certificate chain, hostname validation, expiration, supported protocols and cipher suites. Open the Certificate, Protocols and Ciphers tabs for the underlying observations.
The headers grade covers Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Additional observations include cross-origin policies, server information and cookie attributes.
No. A grade describes the configuration observed at the time of the scan, within the checks performed. WebSec0 does not test application logic, authentication or all possible vulnerabilities. Weakness findings are configuration-based indicators, not proof of exploitability. Incomplete checks remain marked in the report.
Scans are not listed in public history unless you select “Include in public history”. An unlisted report is still accessible to anyone with its report link while it remains cached. Unlisted does not mean access-controlled.
Yes. WebSec0 is MIT-licensed and the hosted scanner requires no account. You can inspect the source, self-host the application or use the JSON API. Request limits apply to protect the service.
Clarity starts with a check