Is your website leaving the door open?
A free security check for small-business websites. In about 15 seconds you get the common security gaps, what each one means, and how to fix it.
Want to see one first?
What we check
Common gaps that are easy to overlook and usually quick to fix. Every finding shows the actual evidence we saw.
HTTPS & certificate
HTTPS works, http:// redirects to it, the certificate is trusted and not about to expire, modern TLS, no insecure mixed content.
Security headers
HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Email spoofing protection
SPF, DMARC policy, and DKIM on common selectors, so scammers can't easily send fake emails "from" your business.
Information leaks
Software version banners, public folder listings, and a short list of files that should never be public, like .env and .git.
Cookies
Whether cookies use the Secure, HttpOnly, and SameSite flags that protect logged-in sessions.
How it works
No sign-up and nothing to install.
- Enter your websiteConfirm it's yours (or you have permission), then start the check.
- We look, we don't pokePlain code reads what any visitor could see: headers, certificate, public DNS, and a few well-known paths.
- Get a plain-English reportA 0–100 score with the math shown, an A–F grade, and what each issue means and how to fix it.
Want the gaps fixed?
SiteSafeCheck is built by Nick Castro, a web developer who fixes the common website security gaps for small businesses. He's upfront about what he does and doesn't do.
One-time fix · $250–$500
Nick fixes the gaps your report found:
- Security headers
- HTTPS / SSL setup and redirects
- SPF, DKIM and DMARC email protection
- Hiding software version banners
- Cookie security flags
Monthly re-scan & watch · $50–$100/mo
Nick re-runs the check every month and tells you in plain English what changed, including certificates getting close to expiring.
Part of a website package
Getting a new site or a refresh from Nick? These protections can be bundled in.
Referred out
Penetration testing, code audits, malware or breach cleanup, server repairs, and exposed sensitive files go to a specialist. Nick can point you to one.
Questions
Is SiteSafeCheck really free?
Yes. There's no sign-up and no card. Fair-use limits keep it free for everyone.
Is the scan safe to run on my website?
Yes. It's passive: it loads your home page, reads the response headers and certificate, looks up public DNS records, and requests a short list of well-known file paths, about what a normal visitor or search engine does. It never logs in, submits forms, or sends attack traffic. Only check sites you own or have permission to test.
Does a good grade mean my site is secure?
No. A passive check only sees what's publicly visible. A good grade means the common configuration gaps are covered. It can't prove a site is secure or find problems inside your code, plugins, or server.
How is the score calculated?
Every report starts at 100. Each failed check subtracts 15 (high), 8 (medium), or 3 (low) points, and warnings subtract about half. Any high-severity failure caps the score at 69. 90+ is an A, 80+ a B, 70+ a C, 60+ a D, and below 60 an F.
What does it store?
The domain you check and its report are cached for about 10 minutes so repeat checks are instant. A hashed version of your IP address is kept for about a day for rate limits. The domain and its findings (nothing about you) are sent to Google's Gemini API to write the plain-English explanations. Nothing is sold. Details are on the privacy page.
Can you fix what the report finds?
Nick Castro can fix the common configuration gaps: security headers, HTTPS/SSL setup, SPF, DKIM and DMARC email protection, hiding version banners, and cookie flags. A one-time fix is $250 to $500, and a monthly re-scan and watch is $50 to $100 a month. Exposed files, penetration testing, code audits, and breach or malware cleanup are referred to specialists.