m3u8-player.net

Scanned:

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Watch this site's security

We'll email you if its security slips: a new vulnerability, an expiring certificate, a blacklisting. No account needed.

Security alerts only. Nothing else, and no email unless something is wrong. Unsubscribe anytime.

Want more than security alerts?

Coming soon

Monitor: daily re-scans across all five axes, instant alerts on new and cert expiry, Telegram & web push, and full history.

Fix what matters first

  1. 1
    Core Web Vitals (PageSpeed)

    Improve Core Web Vitals — see the PageSpeed Insights report for specifics.

    +8
  2. 2
    HSTS (Strict-Transport-Security)How to fix this →

    Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

    +4
  3. 3
    Content-Security-PolicyHow to fix this →

    Add a Content-Security-Policy to mitigate and injection.

    +2

Recommendations are ranked by their impact on your score.

All checks

Security

85/ 100
  • Pass

    HTTPS & HTTP→HTTPS redirect

    HTTPS available; HTTP redirects to HTTPS

  • Pass

    TLS certificate validity

    Valid; expires in 60 days

    expires 2026-10-25 · WE1

    Good: valid certificate with 30 days or more to expiry

  • Warn

    HSTS (Strict-Transport-Security)

    No Strict-Transport-Security header

    Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

  • Warn

    Content-Security-Policy

    No Content-Security-Policy header

    Add a Content-Security-Policy to mitigate and injection.

  • Pass

    Core security headers

    All present

    present: X-Content-Type-Options, X-Frame-Options, Referrer-Policy
  • Pass

    Mixed content (HTTP on HTTPS)

    No insecure (http://) subresources

  • Pass

    SPF email anti-spoofing

    record present

    v=spf1 include:_spf.mx.cloudflare.net ~all
  • Pass

    DMARC email anti-spoofing

    record present

    v=DMARC1; p=reject;
  • N/A

    Vulnerable front-end libraries

    No recognizable front-end library versions detected

  • N/A

    CMS known vulnerabilities

    Next.js detected, but no reliable version — no vulnerability claim

Performance

63/ 100
  • Pass

    Time to First Byte

    Fast

    75 ms

    Fast: under 800 ms · Moderate: 800–1800 ms · Slow: over 1800 ms

  • Pass

    Text compression

    Enabled

    br
  • Pass

    HTTP/2 or HTTP/3

    Modern

    HTTP/2.0 (HTTP/3 advertised)

    Modern: HTTP/2 or HTTP/3 · Outdated: HTTP/1.1 or older

  • Pass

    Cache-Control

    Present

    public, max-age=0, must-revalidate
  • Fail

    Core Web Vitals (PageSpeed)

    perf 63/100, 1.4 s, 0.43 (field)

    Good: 2.5 s or less · 0.1 or less · INP 200 ms or less

    Improve Core Web Vitals — see the PageSpeed Insights report for specifics.

SEO

100/ 100
  • Pass

    Page title

    63 characters

    M3U8 Downloader | M3U8 to MP4 | M3U8 Player - Free Online Tools

    Good: 10–70 characters

  • Pass

    Meta description

    125 characters

    Free M3U8 downloader, converter and player. Download M3U8 streams, convert to MP4, play HLS online. No installation required.

    Good: 50–160 characters

  • Pass

    Canonical URL

    Present

    https://m3u8-player.net/
  • Pass

    robots.txt

    Present and not blocking

    https://m3u8-player.net/robots.txt
  • Pass
  • Pass

    Single H1

    1 H1 tag(s)

    Professional Online M3U8/HLS Player
  • Pass

    Image alt text

    12/12 images have alt (100%)

    Good: 90% or more with alt text · Poor: under 50%

  • Pass

    Structured data (JSON-LD)

    present

    FAQPage, Question, Answer, HowTo, HowToStep, Organization

This page is clean. What about the rest of the site?

A clean page is a good sign and not a verdict on the site. The faults that cost the most traffic only exist between pages, so a single-page check cannot see them at all.

A full audit crawls up to 100 pages and checks

  • Indexability and crawling
  • On-page and content
  • Technical
  • Structured data and social previews
  • Links
  • Site-wide configuration

Free while in beta ($19 after launch). No domain verification — we only read pages your site already shows everyone.

Infrastructure

100/ 100
  • Pass

    CMS detection

    Detected

    Next.js
  • Pass

    Web server

    Identified

    cloudflare
  • Pass

    CDN detection

    Detected

    Cloudflare
  • Pass

    TLS version

    Up to date

    TLS 1.3

    Up to date: TLS 1.2 or 1.3 · Deprecated: TLS 1.0 or 1.1

  • Pass

    IPv6 (AAAA record)

    AAAA record present

    2606:4700:3030::6815:1d10

Reputation

100/ 100
  • Pass

    Google Safe Browsing

    Not flagged

    checked: Google Safe Browsing
  • Pass

    Domain blacklist status

    Not on major blocklists

    checked: Spamhaus DBL, SURBL
  • Pass

    Domain age

    Registered ~11 months ago

    2025-09-09

    Good: 90 days or more since registration

  • Pass

    Domain expiry

    Expires in 378 days

    2027-09-09

    Good: 30 days or more to expiry

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Go deeper

This scan is passive. An attacker won't be.

The free scan reads what your site shows everyone. A Deep Audit does what an attacker does: it actively probes your verified site for what's really exposed.

This free scan (passive)

  • Security score
  • Known-CVE counts
  • Security headers
  • TLS & certificate
  • Blacklist & Safe Browsing

Deep Audit: active scan of your verified site

  • Per-CVE breakdown: IDs, severity, exploit availability, fix version
  • Exposed files (.git, .env, backups)
  • Directory listing
  • Open admin panels
  • Open ports
  • Subdomain exposure
  • Prioritized fix plan
  • Full PDF report

What we can't check without your permission

These need active probing of your site: exposed .git/.env/backups, open admin panels, open ports, forgotten subdomains. Verify your domain and we'll show you what an attacker would find.

How it works

  1. Verify your domain: a file or DNS record, about 2 minutes.
  2. We actively scan it: a few minutes; we email you when it's ready.
  3. Get your full report + PDF.

The deep scan is live and free while we're in beta. Verify your domain and run it now.

Active checks run only on a domain you've verified as yours, with your consent. We detect, never exploit. Free in beta; $39 one-time after launch, no subscription, and early adopters keep the deep scan free.

Run a free deep scan

Share this report

Request removal of this report

Recently checked

See all reports →