We analyze your website security in seconds. 15 security checks, detailed report with findings, prioritized recommendations and a final grade downloadable as PDF.
Start Free AnalysisWe perform a passive analysis of 15 critical security points without any intrusion into your system.
Detect if the server exposes version, technology, or sensitive paths info that could facilitate an attack.
MediumVerify certificate validity, expiration date, and if the most secure TLS protocol available is used.
CriticalCheck that the site correctly redirects from HTTP to HTTPS, complying with basic PCI DSS requirements.
HighIdentify resources (images, scripts, styles) loaded via HTTP on HTTPS pages, which compromise security.
HighAnalyze HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
HighVerify if the site is protected against clickjacking attacks using X-Frame-Options or CSP frame-ancestors.
MediumEvaluate the presence and quality of the CSP policy: directives, use of unsafe-inline, and effectiveness against XSS.
HighVerify that all cookies have the HttpOnly, Secure, and SameSite flags configured correctly.
HighDetect presence of cookie consent banner, privacy policy link, and analytics use without consent.
MediumAnalyze if scripts and styles loaded from external CDNs have the Subresource Integrity attribute.
MediumVerify if the domain has DNSSEC enabled to protect against DNS cache poisoning attacks.
MediumReview the presence and configuration of the robots.txt file to control bot and scraper access.
LowSearch in the public source code for comments with credentials, CMS versions, or other sensitive data.
MediumVerify if the site restricts browser access to sensitive APIs like camera, microphone, and geolocation.
LowDetect if the server exposes the backend software name and version (X-Powered-By, framework headers).
MediumEnter your details and the URL of your site. The analysis takes approximately 30 seconds.
Please wait. We are verifying 15 security points on your site.
This tool performs only passive public security analysis (HTTP headers query, DNS, SSL certificates, and accessible HTML content). It does not execute exploits, injections, or intrusive tests. Using this tool on websites without authorization may be contrary to current legislation. Berlo is not responsible for the misuse of this tool.