Website security scanner

Find what a hacker would find on your website — before they do.

A free website security scan for the vulnerabilities attackers actually target — outdated software, known security flaws (Common Vulnerabilities and Exposures, CVEs), exposed files.

  • Free scan
  • No sign-up
  • Results in 30s

Passive checks only — we read publicly available data and never intrusively probe a website. How we scan

example.com

Example

2 security issues found

jQuery 1.8.2 — 5 known

70/ 100 · overall score
  • Security46
  • Performance82
  • SEO71
  • Infrastructure88
  • Reputation96

An outdated library with 5 known exploits — exactly what automated attacks scan for.

Our advantages

Security depth most checkers skip

Most checkers look for a padlock and call it a day. We go where attackers go — matching the exact library and CMS versions your website runs against known (OSV.dev, NVD, GitHub Advisory), and flagging what they'd exploit first.

  • Known in your JS libraries & CMS version
  • Missing or weak security headers (, , X-Frame-Options)
  • Exposed sensitive files (.git, backups, logs)
  • Weak TLS / certificate problems
  • Blacklisting & Google Safe Browsing flags
  • Insecure cookies & mixed content
Example

jQuery 1.8.2 — 5 known CVEs

Fix: upgrade to 3.x

Why it matters

What a secure website gets you

  • Find the holes before an attacker does

    See the exposed files, weak headers, and vulnerable libraries an attacker would exploit — and close them first.

  • Stay out of the next breach

    Outdated software and known are how sites get defaced, ransomed, or leaked. Catch them before they're used against you.

  • Keep off the blacklists

    A hacked or flagged website gets delisted by Google and blocked by email providers. Spot what puts you there before it does.

  • Earn customer trust

    A secure website is table stakes for buyers. Prove yours won't leak their data.

  • Rank and load better, too

    The same scan flags the performance and SEO issues quietly costing you traffic — health context alongside the security.

Coverage

What we scan for

The vulnerabilities and misconfigurations an attacker would look for — plus the health context that keeps you fast and findable.

Security

The core of the scan: the holes an attacker would find and exploit first.

Active checks — port scanning and probing for exposed files — run only after you verify domain ownership.

We also check the rest

Performance

Core Web Vitals and delivery, measured via the PageSpeed Insights API.

SEO

The on-page fundamentals search engines expect to find.

Infrastructure

What powers the website — server, CDN, DNS, and TLS setup.

Reputation

Whether the domain is trusted, clean, and in good standing.

  • 5

    axes

  • 32

    checks per scan

Built on trusted, open data sources

  • Google PageSpeed Insights
  • Google Safe Browsing
  • retire.js
  • OSV.dev
  • NVD
  • GitHub Advisory

Where we fit

Between shallow health checkers and scary enterprise scanners

Between shallow health checkers and scary enterprise scanners
CapabilityHealth checkersEnterprise scannersCheckWeb
Real vulnerability & detectionnoyesyes
Finds exposed files & security misconfigsnoyesyes
Plain-English findings, no jargonyesnoyes
One readable 0–100 scoreyesnoyes
Free scan on any website (passive)variesnoyes
No sign-up, no emailvariesnoyes
Public shareable report + badgenonoyes
Continuous security monitoringnoyesyes

…the depth you need, without the enterprise price tag or the sign-up wall.

The differentiator

Close the holes that matter first

We rank the holes by risk, so you close the most dangerous first — not a wall of 40 issues.

Example
74
Today
89
After closing these 3
  1. 1Upgrade jQuery 1.8.2 → 3.x (5 known CVEs)+6
  2. 2Add missing security headers (, )+5
  3. 3Remove exposed .git directory+4

Ranked by severity × exposure — effort goes where the risk is.

Share your results

Every scan becomes a shareable public report

Each result gets its own clean, shareable page at chkweb.com/report/<domain>, plus an embeddable badge that links back to it.

  • Indexable by design

    Reports are server-rendered pages that search engines and AI answer engines can read and cite.

  • A trust badge for your website

    Embed the “Verified” badge to show visitors your security score at a glance — one click opens the full report behind it.

  • One-click sharing

    Share to X or LinkedIn, or copy the link — the score travels with it.

Scan my website
Examplechkweb.com/report/acme.com
Verified

Security score

Embeddable badge

CheckWeb89
<a href="https://chkweb.com/report/acme.com"><img src="https://chkweb.com/badge/acme.com.svg" alt="Website security checked by CheckWeb" /></a>

Illustrative preview — run a scan to generate your own.

Pricing

Simple, honest pricing

Start free. The deep scan is free while we're in early access — a one-time audit after launch, or subscribe for continuous monitoring.

Quick scan

Available now
$0

A passive security scan whenever you need one.

  • On-demand passive scan
  • Public shareable report
  • Security score
  • Core set of checks
Scan my website — free

Deep Audit

Early access
$0

$39 one-time after launch · no subscription

Actively scan your own verified site: exposed files, admin panels, ports, subdomains, per- breakdown, PDF. Free in early access — early adopters keep it free.

  • Verify your domain, then active scan
  • Exposed files, open ports, admin panels
  • Full per- breakdown
  • Prioritized fix list
  • Full PDF report
Run a deep scan

Monitor

Coming soon
$19/mo

Continuous security monitoring and alerts.

  • Daily re-scan
  • Alerts on new , cert expiry, blacklisting
  • Watch SSL, domain & exposed files
  • History & API access

Agency

Coming soon
$89/mo

For teams managing many websites.

  • Everything in Monitor
  • Multiple websites
  • White-label reports & badge
  • Team access

The free scan is passive and works on any site. Deep Audit and Monitor scan your own site actively (exposed files, ports, admin panels) — unlocked with a one-time domain verification.

Prices in USD. The free scan and the deep scan both work today — the deep scan is free while we're in early access. Monitoring plans arrive in a later phase; leave your email and we'll tell you the day they launch.

Transparency

How we score your security

A single number is only useful if you trust it. Our weighting is public — and tilted toward security.

Every check returns pass, warn, or fail and carries a weight. Each axis score is the weighted share of its checks; the overall score is a weighted sum of the five axes — and Security is the heaviest at 35%, because it's the highest risk to you if it fails. Critical security failures — a broken certificate, no HTTPS, a blacklisted domain — cap the score outright. The full methodology is published, no black box.

How each check is scored

  • PassMeets the best-practice bar for that check.

  • WarnWorks, but partial or below the ideal — worth improving.

  • FailMissing or actively harmful — a priority fix.

Draft weights — calibrated on real-world data and always published.

How the 100 points split across axes

  • Security 35%

    Highest risk to the owner if it fails.

  • Performance 20%

    Real impact on conversion and SEO, but rarely existential.

  • SEO 20%

    Visibility and organic traffic.

  • Reputation 15%

    Rare, but blacklisting is critical.

  • Infrastructure 10%

    Mostly informational context.

Honest by design: hard limits

Some failures are too serious to average away. A website with a broken or untrusted certificate can't score above 50. No HTTPS at all caps you at 40. A blacklisted domain is capped too. That's why our scores can be genuinely low — and why a high CheckWeb score actually means something.

Good (80–100)Needs work (50–79)Poor (0–49)

Would you trust a website that scores 42? Your visitors decide in seconds.

FAQ

Frequently asked questions

The short answers. More detail lands as we ship.

Can you scan my website for vulnerabilities?

Yes — that's the core of it. We detect known-vulnerable JavaScript libraries and CMS versions (matched to real ), missing security headers, TLS and certificate problems, exposed sensitive files, and blacklisting. Free, in plain English, no sign-up.

Is it safe — do you attack my website?

No. The free scan is strictly passive: we read publicly available data — response headers, the returned HTML, DNS, the TLS certificate, the library versions a page loads — exactly what any browser or search crawler sees. We never brute-force, send exploit payloads, or probe hidden paths. Deeper active checks (probing for exposed files, admin panels, or open ports) run only after you verify you own the domain.

Do you scan WordPress sites?

Yes. We fingerprint WordPress and its version, then flag the known affecting that core version as a security finding — with the count and severity — alongside your security headers, TLS, and blacklist status. This covers the WordPress core (and Joomla, Drupal, TYPO3, Magento, PrestaShop, 1C-Bitrix). Plugin- and theme-level coverage is on the way.

What can I see for free vs. after verifying my domain?

Everything passive is free on any website: the security score, vulnerable libraries and CMS versions, headers, TLS, blacklists. Active, intrusive checks — exposed files (.git, backups), open admin panels, port scans — run only on a domain you've verified as your own. That deep scan is live today and free while we're in early access (a one-time $39 audit after launch); continuous Monitor is still coming.

What counts as a vulnerability?

Anything an attacker could use against you: a JavaScript library or CMS version with a known , a missing or misconfigured security header, an expired or weak TLS certificate, an exposed sensitive file, insecure cookies or mixed content, or a domain that's been blacklisted. We report the finding and how to fix it — we don't try to exploit it.

Is the website security check free?

Yes. The public website security check and the score are free, with no sign-up. The Deep Audit — the active scan of your own verified site — is live and free during early access (a one-time $39 audit after launch, no subscription). Continuous Monitor ($19/mo) is coming later.

How is the security score calculated?

Each check returns pass, warn, or fail with a weight. Axis scores are weighted shares; the overall score is a weighted sum of the five axes — weighted toward Security (35%). Critical security failures (a broken certificate, no HTTPS, a blacklisted domain) cap the score outright. The full methodology is published in How we score.

What sources do you use for vulnerabilities?

Open data only — retire.js for front-end libraries, OSV.dev for packages, and NVD plus GitHub Advisory for CMS and server software. No proprietary databases.

How long does a scan take?

Most scans finish in 15–30 seconds. Performance data comes from the PageSpeed Insights API and is cached to stay fast.

How often should I scan my website?

Scan whenever you ship changes, update a plugin, or renew a certificate — new versions bring new . Security isn't a one-time check: a new vulnerability in your stack, a leaked file, or a blacklisting can land any day. Continuous monitoring (coming soon) re-scans for you and alerts you the moment something new appears.

Do you store my data?

The product is built privacy-first and GDPR-aligned. Public reports are indexable by design; anything tied to an account stays under your control.