Know what your website is telling the world.

Get a clear security health score for the protections, domain settings, and public signals visitors can already see.

Public pages only. No account or invasive testing.

No sign-upNo payloadsResults are one-time
WEB SAFE SCORE / REPORTPUBLIC SIGNALS
Protection score84Needs attention
HTTPS & TLSStrong
Content Security PolicyReview
DMARC policyImprove

A useful review of the surface your site already exposes.

Every check is passive or based on a normal public request. Inaccessible checks are marked incomplete—not scored as failures.

HTTPS & transport
TLS, redirects, certificate signals, and mixed content.
Public checks only
Security headers
CSP, HSTS, framing, MIME sniffing, and referrer controls.
Public checks only
Cookies & forms
Public cookie flags, form destinations, and password transport.
Public checks only
Domain configuration
SPF, DMARC, MX, CAA, robots guidance, and sitemap access.
Public checks only
Front-end hygiene
Third-party clues, source map references, and platform signals.
Public checks only
Public page review
A small, same-origin crawl of links already visible on your site.
Public checks only
Built to be carefulDNS pinnedSame-origin crawlStrict request limitsEphemeral results

Scores that show where to focus.

Website protection carries more weight in the overall score. Checks we cannot complete are excluded rather than counted against you.

Website protection
  • HTTPS and TLS
  • Security headers
  • Cookie flags
  • Forms and framing
Domain & email
  • SPF and DMARC
  • MX records
  • CAA policy
  • Canonical destination
Site hygiene
  • Mixed content
  • Source map references
  • Public crawler files
  • Platform signals

A scanner should reduce risk, not create more of it.

Web SafeScore never logs in, submits forms, guesses hidden paths, enumerates users, or attempts exploits. Requests identify the scanner and respect conservative limits.

ALLOW public HTTP(S) pages
ALLOW linked same-origin pages
DENY private and reserved networks
DENY credentials and custom ports
DENY payloads, fuzzing, and exploitation

See your public website through a safer lens.

Run a non-intrusive check and leave with a prioritized list of practical improvements.

Public pages only. No account or invasive testing.

Three steps. No security theater.

We keep the scope intentionally narrow so findings stay understandable and the scanner stays respectful.

  1. 01

    Enter a public website

    We validate DNS and block private, local, reserved, and non-standard destinations.

  2. 02

    We review visible signals

    A small crawler follows same-origin links, with strict page, depth, body, and time limits.

  3. 03

    Get a prioritized report

    Scores are calculated in code. Each finding includes evidence and a safe next step.

Useful signals. Deliberately narrow scope.

Web SafeScore is a non-intrusive website health check, not a penetration-testing service. Its boundaries protect site owners, visitors, and infrastructure.

What the scanner does
  • Requests public HTTP or HTTPS pages as WebSafeScoreBot/1.0.
  • Follows only a small number of links already visible on the same website.
  • Reviews public headers, HTML, TLS details, DNS records, robots.txt, and sitemaps.
  • Stops at 20 HTML pages, two link levels, 32 requests, or the scan deadline.
What it never does
  • Never signs in, submits forms, sends attack payloads, or attempts exploits.
  • Never guesses hidden paths, looks for admin panels, or enumerates users.
  • Never connects to private networks, cloud metadata, reserved addresses, or non-standard ports.
  • Never labels an inaccessible or untested check as a confirmed vulnerability.
Permission, control, and limits
  • Submit only websites you own, administer, or are authorized to review.
  • Site operators can block the identifiable scanner user agent at their server or edge.
  • Automated bulk scanning and attempts to bypass safety limits are prohibited.
  • Results cover a small public sample and are not a guarantee of security or compliance.

Scoring and limitations

Scoring is calculated by versioned application code. Checks that cannot be completed are excluded rather than failed. A short public scan cannot see authenticated areas, server internals, compensating controls, or every route, so findings should be verified before changes are made.