Free tool
security.txt generator
A security.txt file tells researchers whom to write to when they find a hole on your site. Fill in the contact, copy the result and place the file at /.well-known/security.txt.
- Free
- No sign-up
- RFC 9116 format

Questions and answers
What is security.txt?
A plain text file defined by RFC 9116 with a contact for vulnerability reports. A researcher who finds a hole sees whom to tell and does not publish the finding openly.
Is security.txt mandatory?
No, but it is a simple sign of a mature site. Awe Check checks that it exists and has not expired. It is especially useful for sites handling personal data and payments.
Where do I put the file?
At /.well-known/security.txt in the site root. /security.txt also works, but the standard prefers the first path. Serve it as text/plain over HTTPS.
Which fields are required?
Two: Contact and Expires. The rest (languages, policy, PGP key, acknowledgments) are optional.
What Expires date should I use?
No more than a year ahead. Set a reminder to renew it, otherwise the file becomes invalid and Awe Check flags it as a risk.
How do I verify the result?
Run a site check in Awe Check: the security.txt item shows whether the file is found, has a contact and has not expired.
Keep reading
Check the whole site’s protection
In a minute Awe Check tests HTTPS, headers, exposed service files, domain email and laws.