rewordsai.app
Scanned:
Score by axis
Want one of these looked at properly?
This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.
No email, no sign-up. Pick the one you care about.
Watch this site's security
We'll email you if its security slips: a new vulnerability, an expiring certificate, a blacklisting. No account needed.
Security alerts only. Nothing else, and no email unless something is wrong. Unsubscribe anytime.
Want more than security alerts?
Coming soonMonitor: daily re-scans across all five axes, instant alerts on new and cert expiry, Telegram & web push, and full history.
Fix what matters first
- 1Core security headersHow to fix this →+5
Add X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.
- 2HSTS (Strict-Transport-Security)How to fix this →+4
Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.
- 3Core Web Vitals (PageSpeed)+5
Improve Core Web Vitals — see the PageSpeed Insights report for specifics.
- 4+2
- 5Domain age+1
Newly registered domains carry less trust; this improves with age.
Recommendations are ranked by their impact on your score.
All checks
Security
71/ 100- Pass
HTTPS & HTTP→HTTPS redirect
HTTPS available; HTTP redirects to HTTPS
- Pass
TLS certificate validity
Valid; expires in 50 days
expires 2026-10-15 · WE1Good: valid certificate with 30 days or more to expiry
- Warn
HSTS (Strict-Transport-Security)
No Strict-Transport-Security header
Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.
- Warn
Content-Security-Policy
No Content-Security-Policy header
Add a Content-Security-Policy to mitigate and injection.
- Fail
Core security headers
None present
Add X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.
- Pass
Mixed content (HTTP on HTTPS)
No insecure (http://) subresources
- Pass
SPF email anti-spoofing
record present
v=spf1 include:_spf.mx.cloudflare.net ~all - Pass
DMARC email anti-spoofing
record present
v=DMARC1; p=reject; - N/A
Vulnerable front-end libraries
No recognizable front-end library versions detected
- N/A
CMS known vulnerabilities
No CMS detected
Performance
74/ 100- Pass
Time to First Byte
Fast
73 msFast: under 800 ms · Moderate: 800–1800 ms · Slow: over 1800 ms
- Pass
Text compression
Enabled
br - Pass
HTTP/2 or HTTP/3
Modern
HTTP/2.0 (HTTP/3 advertised)Modern: HTTP/2 or HTTP/3 · Outdated: HTTP/1.1 or older
- Pass
Cache-Control
Present
no-store, must-revalidate - Warn
Core Web Vitals (PageSpeed)
perf 93/100, 2.8 s, 0.08 (field)
Good: 2.5 s or less · 0.1 or less · INP 200 ms or less
Improve Core Web Vitals — see the PageSpeed Insights report for specifics.
SEO
100/ 100- Pass
Page title
59 characters
ReWords AI | Edit Text in Images Online | Image Text EditorGood: 10–70 characters
- Pass
Meta description
160 characters
Replace text in finished images online with ReWords AI. Match the original font, style, and background when you edit text in screenshots, posters, or packaging.Good: 50–160 characters
- Pass
- Pass
- Pass
- Pass
Single H1
1 H1 tag(s)
ReWords AI — Edit Existing Text in Images - Pass
Image alt text
12/12 images have alt (100%)
Good: 90% or more with alt text · Poor: under 50%
- Pass
Structured data (JSON-LD)
present
Organization, ImageObject, ContactPoint, WebSite, WebPage, SpeakableSpecification
This page is clean. What about the rest of the site?
A clean page is a good sign and not a verdict on the site. The faults that cost the most traffic only exist between pages, so a single-page check cannot see them at all.
A full audit crawls up to 100 pages and checks
- Indexability and crawling
- On-page and content
- Technical
- Structured data and social previews
- Links
- Site-wide configuration
Free while in beta ($19 after launch). No domain verification — we only read pages your site already shows everyone.
Infrastructure
100/ 100- N/A
CMS detection
No CMS fingerprint detected
- Pass
Web server
Identified
cloudflare - Pass
CDN detection
Detected
Cloudflare - Pass
TLS version
Up to date
TLS 1.3Up to date: TLS 1.2 or 1.3 · Deprecated: TLS 1.0 or 1.1
- Pass
IPv6 (AAAA record)
AAAA record present
2606:4700:3036::6815:4f61
Reputation
92/ 100- Pass
Google Safe Browsing
Not flagged
checked: Google Safe Browsing - Pass
Domain blacklist status
Not on major blocklists
checked: Spamhaus DBL, SURBL - Warn
Domain age
Registered ~1 month ago
2026-07-15Good: 90 days or more since registration
Newly registered domains carry less trust; this improves with age.
- Pass
Domain expiry
Expires in 324 days
2027-07-15Good: 30 days or more to expiry
Want one of these looked at properly?
This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.
No email, no sign-up. Pick the one you care about.
Go deeper
This scan is passive. An attacker won't be.
The free scan reads what your site shows everyone. A Deep Audit does what an attacker does: it actively probes your verified site for what's really exposed.
This free scan (passive)
- Security score
- Known-CVE counts
- Security headers
- TLS & certificate
- Blacklist & Safe Browsing
Deep Audit: active scan of your verified site
- Per-CVE breakdown: IDs, severity, exploit availability, fix version
- Exposed files (.git, .env, backups)
- Directory listing
- Open admin panels
- Open ports
- Subdomain exposure
- Prioritized fix plan
- Full PDF report
What we can't check without your permission
These need active probing of your site: exposed .git/.env/backups, open admin panels, open ports, forgotten subdomains. Verify your domain and we'll show you what an attacker would find.
How it works
- Verify your domain: a file or DNS record, about 2 minutes.
- We actively scan it: a few minutes; we email you when it's ready.
- Get your full report + PDF.
The deep scan is live and free while we're in beta. Verify your domain and run it now.
Active checks run only on a domain you've verified as yours, with your consent. We detect, never exploit. Free in beta; $39 one-time after launch, no subscription, and early adopters keep the deep scan free.
Run a free deep scan