Free Security Scanner

Find vulnerabilities
before attackers do.

SecTest scans your website for security misconfigurations, expired certificates, missing headers, known CVEs, and OWASP Top 10 issues — in under 60 seconds. No account. No credit card. Free.

No account required GDPR safe Results in <60s
sectest.salloq.com — scanner
SSL Certificate PASS
Security Headers 3 MISSING
Content-Security-Policy NOT SET
Open Ports 2 EXPOSED
Mixed Content PASS
CMS Version OUTDATED
47
security checks per scan
<60s
average scan time
OWASP
Top 10 coverage
100%
free, no limits
Coverage

47 checks across 6 categories

Every scan covers the full attack surface — from TLS configuration and HTTP headers to exposed paths, CMS versions, and DNS records.

SSL / TLS

Certificate validity, expiry, chain of trust, weak ciphers, and protocol version checks.

Certificate expiry
TLS 1.0 / 1.1 detection
Weak cipher suites
HSTS enforcement

HTTP Security Headers

Detects missing or misconfigured headers that expose your site to XSS, clickjacking, and MIME sniffing.

Content-Security-Policy
X-Frame-Options
X-Content-Type-Options
Referrer-Policy

Open Ports & Services

Scans common ports for unexpected exposure of databases, admin panels, and debug endpoints.

Common port scan
Admin panel exposure
Debug endpoint detection
phpinfo() / .env leaks

CMS & Software Versions

Fingerprints your CMS, frameworks, and plugins then cross-references against known CVEs.

WordPress / WooCommerce
Plugin version checks
jQuery / library versions
CVE cross-reference

DNS & Email Security

Validates SPF, DKIM, and DMARC records to protect your domain from spoofing and phishing attacks.

SPF record validation
DMARC policy check
DKIM configuration
Zone transfer exposure

Content & Injection

Tests for mixed content, reflected XSS indicators, directory listing, and common injection vectors.

Mixed HTTP/HTTPS content
Directory listing
Reflected XSS indicators
Common injection paths
Process

Scan in three steps

No installation, no signup. Paste a URL and get actionable results.

01 — INPUT

Enter your URL

Paste any publicly accessible URL — your homepage, checkout page, or API endpoint. HTTP and HTTPS both work.

02 — SCAN

We run 47 checks

Our scanner probes SSL configuration, HTTP headers, DNS records, open ports, software versions, and known vulnerability patterns.

03 — REPORT

Get your report

Results arrive in under 60 seconds with a security score, severity-ranked findings, and plain-English remediation steps for each issue.

Output

A real report, not a dashboard

Every finding includes a severity rating, what was found, why it matters, and exactly how to fix it — no security expertise required.

scan-report — example.com
62

Security Score

12 issues found · 3 critical

HIGH
3
MED
5
LOW
2
INFO
2
findings — example.com 62 / 100
Finding Category Severity
Missing Content-Security-Policy Headers HIGH FAIL
TLS 1.0 still accepted SSL/TLS HIGH FAIL
Port 3306 (MySQL) exposed Ports HIGH FAIL
WordPress 6.3.1 (outdated) CMS MED WARN
Missing DMARC record DNS MED WARN
SSL Certificate valid SSL/TLS PASS
Plain-English explanation for every finding
Step-by-step remediation instructions
Shareable report link — send to your dev team
Re-scan after fixes to track your score over time

Your site is
probably vulnerable.
Let's find out.

Most sites fail at least 3 security checks on first scan. It takes 60 seconds to know where you stand.

FREE · NO ACCOUNT · NO CREDIT CARD · RESULTS IN <60 SECONDS

Always free

No plans, no limits, no upsells. SecTest is a free tool from Salloq Software.

Instant results

47 checks run in parallel. Most scans complete in under 60 seconds.

Non-intrusive

Read-only passive scanning. We never attempt to exploit anything we find.