Free Tool · Passive Analysis

PenTest
Tool

We analyze your website security in seconds. 15 security checks, detailed report with findings, prioritized recommendations and a final grade downloadable as PDF.

Start Free Analysis
15
Checks
A–F
Grade
PDF
PDF Report
$0
Free

What we check?

We perform a passive analysis of 15 critical security points without any intrusion into your system.

Server Config

Detect if the server exposes version, technology, or sensitive paths info that could facilitate an attack.

Medium

SSL/TLS Certificate

Verify certificate validity, expiration date, and if the most secure TLS protocol available is used.

Critical

HTTPS Forced (PCI DSS)

Check that the site correctly redirects from HTTP to HTTPS, complying with basic PCI DSS requirements.

High

Mixed Content

Identify resources (images, scripts, styles) loaded via HTTP on HTTPS pages, which compromise security.

High

HTTP Security Headers

Analyze HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

High

Clickjacking Protection

Verify if the site is protected against clickjacking attacks using X-Frame-Options or CSP frame-ancestors.

Medium

Content Security Policy

Evaluate the presence and quality of the CSP policy: directives, use of unsafe-inline, and effectiveness against XSS.

High

Cookies Security

Verify that all cookies have the HttpOnly, Secure, and SameSite flags configured correctly.

High

GDPR Compliance

Detect presence of cookie consent banner, privacy policy link, and analytics use without consent.

Medium

External Resources SRI

Analyze if scripts and styles loaded from external CDNs have the Subresource Integrity attribute.

Medium

DNSSEC Configuration

Verify if the domain has DNSSEC enabled to protect against DNS cache poisoning attacks.

Medium

Anti-Scraping Protection

Review the presence and configuration of the robots.txt file to control bot and scraper access.

Low

Info Disclosure

Search in the public source code for comments with credentials, CMS versions, or other sensitive data.

Medium

Permissions-Policy

Verify if the site restricts browser access to sensitive APIs like camera, microphone, and geolocation.

Low

Exposed Web Software

Detect if the server exposes the backend software name and version (X-Powered-By, framework headers).

Medium

Start Security Analysis

Enter your details and the URL of your site. The analysis takes approximately 30 seconds.

🔍 Analyzing security...

Please wait. We are verifying 15 security points on your site.

0%
0
/ 100

Security Report