Check CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Paste any public website URL.
Click Run — results appear in seconds.
Review the report and apply the fixes.
19-point passive security check. API key leak detection, security headers, .env exposure, source maps.
Verify HTTPS and HSTS configuration. SSL is a trust signal for Google, AI assistants, and your users.
Scan JavaScript bundles for exposed secrets: Stripe, OpenAI, AWS, Supabase, and 13 more patterns.
This free tool checks one signal. The full audit scores 25+ signals, monitors ChatGPT and Perplexity for your brand, and ships fix files.