Free tool

security.txt generator

A security.txt file tells researchers whom to write to when they find a hole on your site. Fill in the contact, copy the result and place the file at /.well-known/security.txt.

  • Free
  • No sign-up
  • RFC 9116 format
1Contact and expiry
2Extras

Questions and answers

What is security.txt?

A plain text file defined by RFC 9116 with a contact for vulnerability reports. A researcher who finds a hole sees whom to tell and does not publish the finding openly.

Is security.txt mandatory?

No, but it is a simple sign of a mature site. Awe Check checks that it exists and has not expired. It is especially useful for sites handling personal data and payments.

Where do I put the file?

At /.well-known/security.txt in the site root. /security.txt also works, but the standard prefers the first path. Serve it as text/plain over HTTPS.

Which fields are required?

Two: Contact and Expires. The rest (languages, policy, PGP key, acknowledgments) are optional.

What Expires date should I use?

No more than a year ahead. Set a reminder to renew it, otherwise the file becomes invalid and Awe Check flags it as a risk.

How do I verify the result?

Run a site check in Awe Check: the security.txt item shows whether the file is found, has a contact and has not expired.

Check the whole site’s protection

In a minute Awe Check tests HTTPS, headers, exposed service files, domain email and laws.

Check a site for free