SecurityScan
What SecurityScan checks
Every scan runs these checks from outside your site, the way a visitor and their browser see it. Each page below explains one check in detail.
Cookie Consent Checker
Find tracking cookies set before a visitor consents, a banner without a reject button, and forms with no consent checkbox. Free cookie consent check.
Security Headers Checker
See which HTTP security headers your site sends, including HSTS, Content-Security-Policy, X-Frame-Options and Referrer-Policy, with the value to add.
SSL Certificate & HTTPS Checker
Check that your site has a valid TLS certificate, when it expires, and whether plain HTTP redirects to HTTPS. Free SSL check with ongoing monitoring.
Outdated JavaScript Library Scanner
Detect old versions of jQuery, Bootstrap, AngularJS, Lodash, Moment.js and other libraries your pages load, with the known CVEs for each.
Exposed Files & Server Configuration Check
Find .git folders, .env files, logs and config files reachable from the web, plus version-revealing headers, risky HTTP methods, open CORS and weak cookies.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.