Free website security review
Your website reveals more
than you think.
Your site could expose vulnerable plugins, public usernames and email addresses—valuable clues for phishing and targeted marketing.
See what your website is giving away.
A security review. Not a break-in.
No exploit attempts. No login attempts. No access to private areas.
We only review publicly available information and your site’s security posture.
Waiting for the first public observations…
Email me the full report ↓- Server software
- Waiting for scanner
- Server details reveal the technology behind your site.
- PHP version
- Waiting for scanner
- Older PHP releases may no longer receive security fixes.
- WordPress version
- Waiting for scanner
- A public version can point to known vulnerabilities.
- Plugins found
- Waiting for scanner
- Visible plugins reveal which components need review.
- Cloudflare
- Waiting for scanner
- An edge service may shield your origin—not guarantee safety.
- Remote IP
- Waiting for scanner
- The visible address may belong to a proxy, not your origin.
- Plugins & version hints
- Waiting for scanner
- Public versions can reveal known vulnerabilities; hints still need confirmation.
Hosting, email security & more
- Hosting provider
- Waiting for scanner
- Hosting clues can help tailor convincing impersonation messages.
- Public author accounts
- Waiting for scanner
- Public account clues can help personalize phishing.
- SPF / email policy
- Waiting for scanner
- SPF helps limit who can send mail using your domain.
- DKIM / email signing
- Waiting for scanner
- Signatures help authenticate email. Unknown selectors limit this check.
- HTTPS
- Waiting for scanner
- HTTPS encrypts traffic; it does not prove a site is secure.
- HTTP version
- Waiting for scanner
- The connection protocol adds to your public technology footprint.
- Redirects
- Waiting for scanner
- Redirects show where visitors and their connections are sent.
- Security headers
- Waiting for scanner
- These tell browsers which protective rules to apply.
Public observations—not proof of a vulnerability. Some details may be hidden or unknown. We show account counts, not identities.
Check your inbox
Upload this plain text file at the exact HTTPS address. No redirects.
File contents:
The full review uses about 1,000 requests, gently spaced over 30–60 minutes after verification. No exploit or login attempts.
Follow along here, or close the tab. We’ll email your finished report.