Free website security check
See what an outsider can find on your website
Start a free external website security assessment. No card, no install on your site, no credentials used. Every finding arrives with its evidence.
Type your address below. It goes straight through to the assessment form, so the domain is typed once. There is no card, nothing is installed on your site, and no credentials are used.
Already have an account? Sign in and go straight to your assessments.
What the free assessment gives you
The full external view. DNS and email configuration, TLS and certificates, HTTP security headers, cookies, exposed subdomains, files, endpoints and other externally reachable surface. Not a reduced sample.
Four assessments a month, on one domain. Enough to fix something and check that the fix worked, which is the loop the product is built around. An assessment that cannot be completed does not use the allowance.
Thirty days of score history. So a change is visible rather than asserted.
Every finding with its evidence. The observation that produced it, a severity, a confidence level, and the specific change that resolves it — in language that does not require a security background to act on.
The report in your account. Not a trial, not a watermarked excerpt. It is the same report every plan gets.
What happens after you type your address
1. Create an account. An email address and a password. This is what the report is attached to and what lets you come back to it.
2. Verify the address. A one-time code by email. It keeps the free tier from being a way to run unlimited anonymous assessments against other people's sites.
3. Start the assessment. The address you typed is already filled in. It runs at the basic level straight away — no proof of ownership needed.
4. Optionally prove you control the domain. A verification record in your own DNS unlocks the full check surface: the checks that probe your site more deeply. It is worth doing if the site is yours.
Why an account is required, plainly
- A report needs somewhere to live. Without an account there is no way to save one, email it, or come back after a fix — so you would get a result you cannot act on.
- An assessment consumes real work against a real host. An open, unauthenticated scanner with no per-source limit is not something we are willing to put on the internet.
- Account verification is also what keeps the free tier from being used to scan third-party domains at volume.
What a free assessment will not tell you
No account means no anonymous check — and even signed in, this is one view
- Nothing behind a login. No credentials are used, so your admin area, member pages and authenticated API surface are not assessed.
- No source code review and no application logic testing. A flaw no external request can reach is outside this method.
- No version-to-vulnerability matching. A disclosed technology version is reported as an observation about what is published, not as a list of what to patch.
- No guarantee. An assessment reports what was observable from outside, at one moment, by one method. A clean report is not a certification and not a promise that the site is secure.
- Unless you verify the domain, the deeper checks do not run. A basic assessment is a genuine external assessment, and the report says at the top which level it ran at.
The methodology is the full version of this, including the request budget, the permitted methods, and how false positives are handled.
If you would rather look before you sign up
Read a real report
A complete assessment of a domain we own, every finding and all of the evidence, published in full. Nothing is redacted and nothing is summarised away, so you can see the actual shape of the output before you commit to anything.
See what the paid plans add
More domains, more assessments, longer history, PDF export and automatic re-assessment. The comparison table on that page is read from the same plan catalogue the billing system charges against.
Read the methodology
What the engine sends, what it refuses to send, the ownership verification model, and the scan depth limits. Every figure on it is read from the running configuration.
Read the security model
How assessment data and reports are handled, who can see a report, and how to report a vulnerability in Soryvex itself.