SSL & Security Audit
See your SSL certificate's validity and four security headers on one screen, no sign-up needed.
This tool connects to your site over HTTPS and checks two things: the validity of your SSL/TLS certificate (who issued it, when it expires) and four security headers returned by your server. HSTS (Strict-Transport-Security) tells the browser to only connect over an encrypted connection for a set period. CSP (Content-Security-Policy) restricts which sources scripts and styles may load from, making injection attacks (XSS) harder to pull off.
X-Content-Type-Options: nosniff stops the browser from interpreting a file as a different type than declared (MIME-sniffing). Referrer-Policy controls how much page information gets sent to other sites when a link is clicked. These four headers work independently, if one is missing the site still loads, but protection against certain attack types weakens.
The audit reads whatever response your server returns at that moment, if your certificate is close to expiry or a header is missing, it shows up immediately. This isn't a penetration test though, it only checks whether widely accepted baseline protections are switched on; it doesn't sum up your site's entire security posture on its own.
How to use it
- Enter your site's address, starting with https://.
- Start the audit and let it read the certificate and four headers.
- Check the certificate's expiry date.
- See which header, if any, is flagged as missing.
- Add the missing header via your server or CDN panel, then re-check.
FAQ
If my certificate is valid, is there anything else to worry about?
Yes, a certificate only proves the connection is encrypted; headers like HSTS and CSP add separate layers against different attack types, and one doesn't substitute for the other.
Does a missing CSP put my site at immediate risk?
A missing CSP isn't a vulnerability by itself, but it means there's no defence layer against injection attacks (XSS); it matters most on pages that accept user input, like forms.
Will this audit renew my certificate?
No, the tool only reads and reports the current state; renewing a certificate or adding a header is done from your server's or CDN's own panel.
If every header shows green, is my site fully secure?
No, these four headers are common baseline protections; a thorough security review also needs to look at server configuration, dependencies, and application code.
