Run a directional passive audit of a public website. Review SSL certificates, selected DNS records, security headers, reputation signals, and potential secret patterns in public JavaScript. Get an A+ to F grade with plain-English explanations. No paid plan.
Verify certificate validity, expiration date, issuer, and chain. Get warnings before certificates expire.
Check A, NS, MX, SPF, DMARC, and common DKIM selectors. DNSSEC, CAA, message alignment, and end-to-end deliverability require separate tools and tests.
Analyze HSTS, Content-Security-Policy, X-Frame-Options, and other security headers that protect against attacks.
Review public JavaScript for hundreds of credential-like patterns associated with AWS, Stripe, Firebase, OpenAI, GitHub, and other providers. Confirm every result before acting.
Review domain and resolved-IP reputation results where configured providers return usable data. Confirm important findings with the named source.
Score HTTPS transport for cross-site script tags declared by the fetched homepage. Review external hosts and informational Subresource Integrity metadata without executing third-party code.
Review homepage HTML signals such as noindex, canonical URL, title, meta description, JSON-LD presence, and document language. These observations do not guarantee search indexing or AI inclusion.