Security is easier to keep than to recover. These are the checks we run on our own sites, packaged so you can point them at yours: each returns a plain, graded verdict and a specific fix, and each runs in seconds. Most cost a few cents per run, and a run against an unreachable target is free.
- Security Headers Audit: HSTS, CSP, frame protection and cookie flags, graded.
- SSL Certificate Audit: certificate expiry, chain, and hostname, from a real handshake.
- CORS Headers Audit: cross-origin policy graded, dangerous reflections named.
- Third-Party Scripts Audit: the external code a page runs, with integrity coverage.
- DNS Records Audit: a full record inventory with CAA and DNSSEC checks.
- Email Deliverability Audit: SPF, DKIM and DMARC graded so your mail lands.
- Domain Typosquat Audit: lookalike domains of yours that are already registered.
These are part of a larger set of tools we build for our own sites and publish for anyone to use. See the full catalog for the rest, including AI-readiness, deliverability, and performance checks.