chkweb.com
Scanned:
Score by axis
Want one of these looked at properly?
This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.
No email, no sign-up. Pick the one you care about.
Watch this site's security
We'll email you if its security slips: a new vulnerability, an expiring certificate, a blacklisting. No account needed.
Security alerts only. Nothing else, and no email unless something is wrong. Unsubscribe anytime.
Want more than security alerts?
Coming soonMonitor: daily re-scans across all five axes, instant alerts on new and cert expiry, Telegram & web push, and full history.
Fix what matters first
- 1+4
- 2Core Web Vitals (PageSpeed)+5
Improve Core Web Vitals — see the PageSpeed Insights report for specifics.
- 3SPF email anti-spoofing+2
Add an TXT record (v=spf1 …) so others can't spoof email from your domain.
- 4Domain age+1
Newly registered domains carry less trust; this improves with age.
- 5IPv6 (AAAA record)+2
Add an AAAA record to serve visitors over IPv6.
Recommendations are ranked by their impact on your score.
All checks
Security
83/ 100- Pass
HTTPS & HTTP→HTTPS redirect
HTTPS available; HTTP redirects to HTTPS
- Pass
TLS certificate validity
Valid; expires in 31 days
expires 2026-10-04 · YE2Good: valid certificate with 30 days or more to expiry
- Pass
HSTS (Strict-Transport-Security)
Present
max-age=31536000; includeSubDomains; preload - Pass
Content-Security-Policy
Present
default-src 'self'; script-src 'self' 'unsafe-inline' https://analytics.chkweb.c… - Pass
Core security headers
All present
present: X-Content-Type-Options, X-Frame-Options, Referrer-Policy - Pass
Mixed content (HTTP on HTTPS)
No insecure (http://) subresources
- Warn
SPF email anti-spoofing
No record
Add an TXT record (v=spf1 …) so others can't spoof email from your domain.
- Pass
DMARC email anti-spoofing
record present
v=DMARC1; p=none; rua=mailto:info@chkweb.com - Fail
Vulnerable front-end libraries
jQuery 1.8.2 — 5 known (max: Medium); Bootstrap 3.1.0 — 6 known (max: Medium)
jquery@1.8.2, bootstrap@3.1.0Upgrade the flagged libraries to a patched version.
- N/A
CMS known vulnerabilities
Next.js detected, but no reliable version — no vulnerability claim
Performance
74/ 100- Pass
Time to First Byte
Fast
313 msFast: under 800 ms · Moderate: 800–1800 ms · Slow: over 1800 ms
- Pass
Text compression
Enabled
gzip - Pass
HTTP/2 or HTTP/3
Modern
HTTP/2.0 (HTTP/3 advertised)Modern: HTTP/2 or HTTP/3 · Outdated: HTTP/1.1 or older
- Pass
Cache-Control
Present
s-maxage=31536000, stale-while-revalidate - Warn
Core Web Vitals (PageSpeed)
perf 72/100, 3.5 s, 0.00 (lab)
Good: 2.5 s or less
Improve Core Web Vitals — see the PageSpeed Insights report for specifics.
SEO
100/ 100- Pass
Page title
63 characters
Free Website Security Check & Scanner, Find CVEs | CheckWebGood: 10–70 characters
- Pass
Meta description
153 characters
Check your website for security vulnerabilities in seconds. Known CVEs, exposed files, weak headers. Free security scan, no sign-up, plain-English fixes.Good: 50–160 characters
- Pass
- Pass
- Pass
- Pass
Single H1
1 H1 tag(s)
Find what a hacker would find on your website before they do. - N/A
Image alt text
No images on the page
- Pass
Structured data (JSON-LD)
present
Organization, ImageObject, Person, WebSite, SoftwareApplication, Offer
This page is clean. What about the rest of the site?
A clean page is a good sign and not a verdict on the site. The faults that cost the most traffic only exist between pages, so a single-page check cannot see them at all.
A full audit crawls up to 100 pages and checks
- Indexability and crawling
- On-page and content
- Technical
- Structured data and social previews
- Links
- Site-wide configuration
Free while in beta ($19 after launch). No domain verification — we only read pages your site already shows everyone.
Infrastructure
77/ 100- Pass
CMS detection
Detected
Next.js - N/A
Web server
Server header not exposed
- N/A
CDN detection
No CDN fingerprint detected
- Pass
TLS version
Up to date
TLS 1.3Up to date: TLS 1.2 or 1.3 · Deprecated: TLS 1.0 or 1.1
- Warn
IPv6 (AAAA record)
No AAAA record
Add an AAAA record to serve visitors over IPv6.
Reputation
92/ 100- Pass
Google Safe Browsing
Not flagged
checked: Google Safe Browsing - Pass
Domain blacklist status
Not on major blocklists
checked: Spamhaus DBL, SURBL - Warn
Domain age
Registered ~2 months ago
2026-07-03Good: 90 days or more since registration
Newly registered domains carry less trust; this improves with age.
- Pass
Domain expiry
Expires in 303 days
2027-07-03Good: 30 days or more to expiry
Want one of these looked at properly?
This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.
No email, no sign-up. Pick the one you care about.
Go deeper
This scan is passive. An attacker won't be.
The free scan reads what your site shows everyone. A Deep Audit does what an attacker does: it actively probes your verified site for what's really exposed.
This free scan (passive)
- Security score
- Known-CVE counts
- Security headers
- TLS & certificate
- Blacklist & Safe Browsing
Deep Audit: active scan of your verified site
- Per-CVE breakdown: IDs, severity, exploit availability, fix version
- Exposed files (.git, .env, backups)
- Directory listing
- Open admin panels
- Open ports
- Subdomain exposure
- Prioritized fix plan
- Full PDF report
What we can't check without your permission
These need active probing of your site: exposed .git/.env/backups, open admin panels, open ports, forgotten subdomains. Verify your domain and we'll show you what an attacker would find.
How it works
- Verify your domain: a file or DNS record, about 2 minutes.
- We actively scan it: a few minutes; we email you when it's ready.
- Get your full report + PDF.
The deep scan is live and free while we're in beta. Verify your domain and run it now.
Active checks run only on a domain you've verified as yours, with your consent. We detect, never exploit. Free in beta; $39 one-time after launch, no subscription, and early adopters keep the deep scan free.
Run a free deep scan