Skip to content
Logo von nextlevels
Request a project
Free · defensive · no signup

SecurityCheck

Enter your site URL – we check public security signals: HTTPS, certificate, headers, cookie flags and common info leaks.

Instant result. Unlock the full report with detail findings via email.

HTTPSTLSHeaderCookiesDisclosureSSLRead-only · 1 Origin

Public http(s) origins only. Private/localhost targets are blocked. No port scans, no exploits.

What the Security Check covers

HTTPS & TLS

We check HTTPS availability, HTTP→HTTPS redirects and certificate validity against your public host:443 – read-only.

Security headers

HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy as delivered by the homepage.

Cookie flags

Visible Set-Cookie headers: Secure, HttpOnly, SameSite. Report only – no cookie theft or replay.

Public info leaks

Server/X-Powered-By banners, homepage directory-listing signals, plus robots.txt and security.txt as informational.

More on our approach: Enterprise software & hardening

FAQ about the Security Check

Your question isn't here? Ask us directly

Is this a penetration test?
No. It is a defensive configuration check against the public origin you submit. No exploits, port scans or credential attacks.
Do I need credentials?
No. We only fetch public URLs and check TLS on host:443.
Why email?
Highlights are immediate. The full detail report is unlocked via email.
What about my data?
The URL is used for the one-off check. Email and results are stored in our CRM only after unlock.
Are private networks scanned?
No. Private, link-local, loopback and metadata IPs (and redirects to them) are blocked.