Security check
Check your SSL/TLS certificate and HTTPS redirect
An expired certificate puts a full-page warning in front of your visitors, and most of them leave. SecurityScan connects to your server, reads the certificate and checks that visitors arriving over plain HTTP are sent to HTTPS.
What the check looks at
A valid certificate
Whether a TLS connection can be established and the certificate is valid. No valid certificate, or an expired one, is a critical finding.
Days until expiry
A certificate that expires in under 30 days is reported as a warning, so there is time to renew it.
HTTP to HTTPS redirect
Whether requests to http:// are redirected to https://.
HSTS
Whether browsers are told to use HTTPS only. Covered in detail on the security headers page.
Why monitoring beats a one-off check
Most hosts renew certificates automatically, until a renewal quietly fails. A one-off check only tells you about today. With a plan, the site is re-scanned weekly or daily, so the 30-day expiry warning reaches you in time.
Questions
- Does it check TLS versions and cipher suites?
- No. It checks the certificate and the HTTPS redirect. For a full protocol and cipher review, use a dedicated TLS testing tool.
- My certificate is valid. Why is there a finding?
- Usually because plain HTTP is not redirected to HTTPS, or the certificate expires in under 30 days.
- Does it work with Let’s Encrypt certificates?
- Yes. Any publicly trusted certificate is checked the same way.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.