HTTPS and certificates
The service checks the HTTPS connection and certificate information using a verified public website origin.
Run authorized injection tests on verified endpoints, inspect security findings and understand recommended repairs with Business.
Verified domains onlyThe service checks the HTTPS connection and certificate information using a verified public website origin.
Review configuration signals such as HSTS, Content Security Policy, and secure cookie attributes, with explanations of findings.
Business users and administrators can select active SQL injection, reflected XSS, CRLF, XPath, template and redirect checks on a verified GET or JSON POST endpoint. Optional test-session headers are encrypted. Stored-XSS rules require explicit permission to create test records. Findings show severity, confidence, observed rule requests and specific repair guidance.
Scans have time and resource limits. DOM-XSS execution, confirmed CSRF and role-based authorization bypass, arbitrary multi-step workflows and exhaustive CVE/TLS coverage are not currently implemented. No automated scan proves a site is secure.
Live configuration checks require domain verification. Detailed reports include certificate evidence, negotiated TLS, policy headers, cookie attributes and recommendations. Active testing can use optional test-session headers on the selected endpoint. Review the selected rules, confidence and evidence; a finding is not proof of exhaustive coverage.
Verify your domain and select the authorized checks included with Business.