About SiteSafeCheck
SiteSafeCheck is a free website security check for small businesses. You enter your website, and it reports common security gaps in plain English: what it found, what that means for you and your customers, and how to fix it.
What it checks
- HTTPS & certificate: whether HTTPS works, http:// redirects to it, the certificate is trusted and not close to expiring, the TLS version, whether old TLS 1.0/1.1 is still accepted, and insecure (mixed) content on the home page.
- Security headers: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Frame-Options / frame-ancestors, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
- Email spoofing protection: SPF, the DMARC policy, DKIM on common selector names (if we don't find it, we say "not found on common selectors", because your provider may use a name we didn't try), and MX records for context.
- Information leaks: software version numbers in headers, public folder listings, a short list of files that should never be public (like
.env,.git, database backups, and phpinfo pages), and whether you publish asecurity.txt. - Cookies: the Secure, HttpOnly, and SameSite flags on cookies your home page sets.
How it checks (passive only)
The scan does what a normal visitor or search engine does. It loads your public home page, reads the response headers and certificate, looks up public DNS records, and requests a short list of well-known file paths. A file only counts as exposed when its contents match what that file really looks like, and we compare against a "page not found" baseline so sites that answer every address with the same page don't get false alarms. We never show the contents of sensitive files.
It never logs in, fills in forms, guesses passwords, or sends attack traffic. Requests identify themselves honestly with the user agent SiteSafeCheck/1.0 (+https://sitesafecheck.com/about).
Only check websites you own or have permission to test.
What it doesn't do
A passive check sees only what's publicly visible. It can't prove a website is secure, and it doesn't look inside your code, plugins, hosting account, or server. It is not a penetration test or a code audit. A good grade means the common configuration gaps are covered, nothing more.
How the score works
Every report starts at 100. Each failed check subtracts 15 points (high severity), 8 (medium), or 3 (low). Warnings subtract 8, 4, or 1. Informational results and checks we couldn't complete subtract nothing. Any high-severity failure, like an untrusted certificate or an exposed .env file, caps the score at 69. Grades: A is 90+, B 80+, C 70+, D 60+, and F below 60. Each report shows exactly which checks cost points.
The AI part
The findings come from plain code, not AI. After the scan, one request to Google's Gemini rewrites the findings that need attention into plain English, tailored to your platform when we can tell what it is. The AI can't add or change findings. If it's unavailable, or says something we don't allow (like calling a site "secure"), we use explanations written by hand.
Who built it
SiteSafeCheck was built by Nick Castro, a web developer who builds websites for small businesses (LinkedIn).
Nick can fix the common gaps this check finds: security headers, HTTPS/SSL setup, SPF, DKIM and DMARC email protection, hiding software version banners, and cookie flags. A one-time fix is $250–$500, a monthly re-scan and watch is $50–$100/month, or it can be bundled into a website package. He doesn't do penetration testing, code audits, malware or breach cleanup, or server repairs. For those, and for exposed sensitive files, he'll refer you to a specialist.