Free Website Security Scan &
Fixed-Price Security Fix Pack
Enter your website address for a free, safe security check. We test your SSL certificate, email protection, browser security settings, and domain records — then show you exactly what needs fixing, in plain English.
Analyzing Domain
Initializing socket connections...
domain.com
OVERALL SECURITY SCORE
Your domain has strong baseline protections, but minor missing parameters leave room for client side or email spoofing vulnerabilities.
AUDIT HIGHLIGHTS
Website Security Risk Estimator
Missing security configurations can leave your website vulnerable to common attacks. Use the sliders below to estimate what a security incident could cost your business based on your traffic and revenue.
Calculations are based on industry aggregates combining remediation expenses, immediate traffic loss, and localized domain spoofing cleanup efforts.
Website Security Fix Pack
We take the issues found for your domain, apply the missing hardening rules, configure practical email authentication records, and return a before-and-after report your client or team can understand.
- ✓Security header and cookie hardening snippets tailored to the scanned domain.
- ✓SPF, DMARC, DKIM, DNSSEC, and CAA DNS action list for email spoofing protection.
- ✓Printable report for clients, insurers, or internal sign-off.
- ✓Everything in Standard Fix Pack — full hardening guide and DNS action list.
- ✦Machine-readable JSON remediation file with exact fix commands and configs per issue.
- ✦Ready-to-paste AI prompt template for Claude, Cursor, or Copilot to apply fixes directly to your server.
Upgrade to WordPress SafePatch
Want us to handle the WordPress fixes as well? Upgrade from the standard report and hardening checklist to an approved SafePatch workflow: backup, staging or maintenance window, AI-assisted patch selection, rollback plan, and post-fix smoke testing before sign-off.
- ✓No unattended live-site changes.
- ✓Agent review before approval.
- ✓Rollback and smoke-test checks included.
Fix My Hacked Website
For active incidents like malicious redirects, injected scripts, spam pages, suspicious admin users, defacement, or Google security warnings. We investigate the scope, repair what we can safely repair, close obvious reinfection paths, and provide a before-and-after recovery report.
- !For suspected active compromise.
- !Cleanup quote depends on scope and platform.
- !No guarantee of instant recovery or future immunity.
AI Security Watch
A lightweight monthly monitoring layer for site owners who want to stay ahead of security drift without managing it themselves. We run a fresh passive scan each month, flag anything that has changed or slipped, and send you a plain-English summary with AI-assisted recommendations.
- ✓Monthly passive security scan — same checks as the free tool, run automatically.
- ✓Security drift alerts — new issues flagged since your last scan, clearly explained.
- ✓AI-assisted recommendations — plain-English action summary each month.
- ✓Priority response on Fix Pack and SafePatch requests.
- ✓10% discount on Fix Pack and SafePatch services while subscribed.
Monitoring and recommendations only. Does not include automatic live-site patching, unlimited cleanup, or guaranteed issue resolution. Cancel anytime.
Support free security reports
This scan is free for small businesses, teams, and site owners. A small donation helps cover testing, hosting, and ongoing security-report improvements.
Security partner ad space
Relevant hosting, backup, DNS, insurance, compliance, and WordPress service partners can sponsor this free reporting tool.
Web Header & Session Cookie Diagnostic Card
Transport Layer Diagnostics & Certificate Lifespan
Domain & Email Authentication (DNS Records)
Instant Server Remediation Snippets
Deploy these rules to harden your servers and domain names against client-side script execution, cookie hijacking, or email phishing attacks.
Detailed Security Findings
Passive scan — no logins, no intrusive tests. Results are indicative only.
Recommended Next Steps
A strong security posture is achievable through server configuration and DNS record updates. Prioritise missing HSTS, CSP, and security headers in your web server configuration, then address email authentication (DMARC, SPF) to prevent domain spoofing. Consider a Web Application Firewall such as Cloudflare for quick wins without server-side changes. The Fix Pack delivers ready-to-deploy configuration snippets for all items marked Failed or Warning above.