Browser & domain trust
HTTPS, certificate expiry, security headers, cookie flags, SPF, DKIM and DMARC.
We check your public website for common security, trust and WordPress issues, then give you a plain-English fix list to send to your web person.
This is not a scary “hack test”. The first version checks visible trust and security signals from the outside.
HTTPS, certificate expiry, security headers, cookie flags, SPF, DKIM and DMARC.
Publicly exposed files, admin paths, debug output, sitemap/robots clues and weak contact paths.
Detects WordPress, visible login/XML-RPC/readme exposure and recommends WordPress-specific follow-up.
Behind the scenes we use our own safe checks first, then OWASP ZAP Baseline, curated Nuclei, testssl.sh and WordPress-specific checks for paid or verified scans.
We do not run brute forcing, destructive tests or intrusive exploitation in the public check.