Free website security checker

Your website’s
security, in focus.

A clearer picture of your website’s security configuration. Check SSL/TLS, certificates and HTTP headers. Know what’s working. See what needs attention.

Free to use. No account needed.

Unlisted by default. Anyone with the report link can view it.

A look beneath the surface
example.comIllustrative report
ATLS configurationProtocols & certificates
BHTTP headersBrowser protections
Understand the finding. Find the next step.

Separate grades. A more useful perspective.

One domain. Multiple layers.

01 / The checks

Small details.
Real security implications.

Move from an unexplained score to specific observations. Each layer gives you another part of the picture.

01

SSL & TLS configuration

See which protocols and cipher suites your server accepts, from legacy SSL to TLS 1.3. Identify outdated options and configuration-based weakness indicators.

ProtocolsCipher suitesForward secrecy
02

Certificate health

Inspect the certificate chain, browser trust, hostname match and expiration. Look into OCSP stapling and certificate transparency observations.

Trust chainExpirationOCSP
03

HTTP security headers

Check HSTS, Content-Security-Policy and other browser protections. Get a dedicated headers grade with the observations behind it.

HSTSCSPPermissions-Policy
04

The surrounding signals

Review security.txt and robots.txt, plus SPF and DMARC policies where available. These add context without changing your TLS or headers grades.

security.txtSPF / DMARCInformational
Explore the full check catalog

02 / From scan to understanding

Less guesswork.
A clearer next step.

Built for developers, site owners and anyone responsible for a website’s configuration.

Illustrative workflow

  1. Start with a domain

    Enter your hostname. WebSec0 makes TLS connections, HTTP requests and DNS queries to inspect its configuration.

  2. Read the evidence

    Review separate TLS and headers grades. Go deeper with certificate details, header values and clearly marked incomplete checks.

  3. Make an informed change

    Use findings and the remediation catalog to plan your fixes. Run another check after updating your configuration.

A configuration check is one part of security. It does not replace an application security assessment.

Open by design

Your workflow.
Your infrastructure.

Use the JSON API, inspect the checks or run your own instance. The same transparent engine, wherever you need it.

Structured. Readable. Ready to use.
Report format
JSON
Independent grades
TLS + Headers
Check catalog
Findings + remediation
Source license
MIT

A few useful answers

Know what
you’re checking.

What does this website security checker test?

WebSec0 checks a hostname’s TLS protocols, cipher suites, certificate chain and HTTP security headers. It also reports security.txt, robots.txt and, where available, SPF and DMARC DNS policies. TLS and HTTP headers receive separate grades; the other observations are informational.

How do I check my SSL certificate and TLS configuration?

Enter your domain above and run a scan. The report shows the certificate chain, hostname validation, expiration, supported protocols and cipher suites. Open the Certificate, Protocols and Ciphers tabs for the underlying observations.

Which HTTP security headers are checked?

The headers grade covers Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Additional observations include cross-origin policies, server information and cookie attributes.

Does an A grade mean my website is completely secure?

No. A grade describes the configuration observed at the time of the scan, within the checks performed. WebSec0 does not test application logic, authentication or all possible vulnerabilities. Weakness findings are configuration-based indicators, not proof of exploitability. Incomplete checks remain marked in the report.

Are my scan results public?

Scans are not listed in public history unless you select “Include in public history”. An unlisted report is still accessible to anyone with its report link while it remains cached. Unlisted does not mean access-controlled.

Is WebSec0 free and open source?

Yes. WebSec0 is MIT-licensed and the hosted scanner requires no account. You can inspect the source, self-host the application or use the JSON API. Request limits apply to protect the service.

Clarity starts with a check

Take a closer look.

Check your website