HTTPS and certificates
The worker checks the HTTPS connection and certificate information using a verified public website origin.
Get a readable view of HTTPS and response-header configuration, without confusing a health check with a full security audit.
Verified domains onlyThe worker checks the HTTPS connection and certificate information using a verified public website origin.
Review configuration signals such as HSTS, Content Security Policy, and secure cookie attributes, with explanations of findings.
These are configuration checks. SQL injection, XSS, and CSRF active testing is a separate planned scanner, not part of these checks. Active scans will require verified ownership and explicit scope. Configuration checks do not patch infrastructure or prove a website is secure.
Live configuration checks require domain verification. Detailed reports include certificate evidence, negotiated TLS, policy headers, cookie attributes and recommendations. Active vulnerability scanning is not available.
Create a workspace or explore an example first.