HTTPS and certificates
The worker checks the HTTPS connection and certificate information using a verified public website origin.
Get a readable view of HTTPS and response-header configuration, without confusing a health check with a full security audit.
Verified domains onlyThe worker checks the HTTPS connection and certificate information using a verified public website origin.
Review configuration signals such as HSTS, Content Security Policy, and secure cookie attributes, with explanations of findings.
Paid users and administrators can select bounded active GET probes on verified domains, with explicit consent. These look for new SQL error signatures and unencoded HTML reflection in existing query parameters. CSRF review checks form-token indicators without submitting forms. Findings require manual validation; no scan proves a site is secure.
Live configuration checks require domain verification. Detailed reports include certificate evidence, negotiated TLS, policy headers, cookie attributes and recommendations. Optional bounded active probes report indicators; exploitation, authenticated attacks and exhaustive vulnerability scanning are not included.
Create a workspace or explore an example first.