Security

How to check a website’s security online: 7 points and a free scan

What to look at so your site is not hacked or fined: HTTPS, security headers, cookies, domain email. A free check in a minute.

Checked against sources: 7 October 2026

  • 7website security points
  • 90 daysLet’s Encrypt certificate life
  • 1 minfree check from outside

The short answer

Website security comes down to seven points: working HTTPS, security headers, cookie flags, protected domain email, up-to-date CMS and plugins, closed service paths and sane access rights. The first four are visible from outside, so you can check them for free from a single address, with no access to the site. That is what Awe Check does.

1. HTTPS with no exceptions

  • The certificate is valid and does not expire this week. Let’s Encrypt certificates live 90 days, so renewal must be automatic.
  • An http:// address redirects to https:// in one hop.
  • No images or scripts load over http://: the browser would show “not secure”.

2. Security headers

These are lines in the server response that switch on protection in the visitor’s browser. The minimum: Strict-Transport-Security with a max-age of at least a year, Content-Security-Policy, X-Content-Type-Options, protection against framing, Referrer-Policy and Permissions-Policy. A full walkthrough with ready-made lines is in the security headers guide.

3. Cookies with flags

A login cookie needs Secure, HttpOnly and SameSite. Without HttpOnly any script injected into the page can read it; without Secure it can travel over an open channel.

4. Domain email

A domain without SPF, DKIM and DMARC lets anyone send mail in its name with a link to a fake login. Customers blame you. The check takes a minute, the fix is three DNS lines.

5. Updates and what is exposed

  • CMS, plugins and themes are current: most breaches come through an old plugin.
  • Default admin paths, backups and files like .env and .git are closed.
  • Server version and verbose errors are hidden.

What Awe Check covers and what it does not

Awe Check reads what the site shows to the outside: HTTPS, headers, cookies, email records, policy and consent. It does not hack the site, scan files for malware or replace an audit with server access. For every issue it names the page and gives a ready fix you can copy.

Frequently asked

How can I check a website’s security for free?

Enter the address in Awe Check: in a minute you get a score, a list of HTTPS, header, cookie and domain email issues, and ready fixes. No sign-up.

Can I check someone else’s site?

Yes. The check reads only public page data, the way a visitor or a search robot does. It does not touch closed areas or passwords.

Will the check find a virus on the site?

No. Malware needs a file scanner on the server. Awe Check finds weak spots from outside, the ones sites are most often entered through.

How often should I check?

After any notable change: a new plugin, a hosting move, a new address. And once a month regardless, because certificates and DNS records expire quietly.

Sources

Check your site

Awe Check shows in a minute which of this is broken on your site and calculates the possible fine.

Check a site