The same outside-in view an attacker gets — turned into clear, actionable results.
Verifies the site loads over encrypted HTTPS and that plain-HTTP visitors are redirected to the secure version.
Checks the five key response headers that block clickjacking, MIME-sniffing and related browser attacks.
Probes for publicly reachable .git folders, .env files, backup copies, admin panels and debug pages.
Validates SPF, DKIM and DMARC records — the trio that stops attackers from sending email as your domain.
Detects WordPress and other stacks, flagging outdated cores, themes and plugins attackers exploit first.
Checks whether risky ports — FTP, Telnet, databases — are reachable from the internet.