Free check
Run a free check on your website right now.
Passive security check on your domain. We look at TLS, security headers, email authentication, and DNS hygiene, and give you an immediate grade plus a plain-English findings list.
60 secondsno signupsame passive checks as paid scans
What you get
Free covers the browser-visible stuff. Paid covers the rest.
The free check is entirely passive: everything we read is what a normal browser would see when it visits your site. Paid scans add active probing and the asset discovery layer.
WhatFree checkPaid scan
TLS version, cipher, certificate hygieneYesYes
HTTP security headers (HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy)YesYes
Email authentication (SPF, DKIM, DMARC, MTA-STS, BIMI)YesYes
DNS records (A, AAAA, MX, NS, CAA) and reverse DNSYesYes
Basic tech fingerprinting from public response headersYesYes
Known-CVE sweep across your whole stack—Yes
Subdomain enumeration and perimeter mapping—Yes
Exposed admin panels, .git/.env, backup-file discovery—Yes
WordPress, WooCommerce, and Shopify-specific evidence checks—Yes
Subdomain takeover checks for known custom-domain providers—Yes
Bounded unauthenticated crawl/fuzz DAST checks—Yes
Bounded public cloud storage listing checks—Yes
Secrets leaked in public JavaScript—Yes
A plain-English report with a prioritised fix list—Yes
Your report, your link
A private URL we don't publish.
Every scan produces a dedicated report at attackedge.io/free-check/report/<token>. The token is long and unguessable, but anyone you send it to can open the report.
Not published, not indexed
- Not linked from anywhere on this site
- Not in search results
- Blocked from search crawlers
Shareable
- Send the link to your IT person, agency, or auditor
- No login needed to open it
- Same view they see is the same view you see
Auto-removed after 7 days
- After 7 days the link stops working
- Run the scan again to produce a fresh one
- Paid plans keep history for you
Want this regularly?
Upgrade to monthly monitoring from A$39.
Solo adds active probing, asset discovery, and the full plain- English report. Cancel anytime from the Stripe portal.