Find what a hacker would find on your website — before they do.
A free website security scan for the vulnerabilities attackers actually target — outdated software, known security flaws (Common Vulnerabilities and Exposures, CVEs), exposed files.
- Free scan
- No sign-up
- Results in 30s
Passive checks only — we read publicly available data and never intrusively probe a website. How we scan
example.com
Example2 security issues found
jQuery 1.8.2 — 5 known
- Security46
- Performance82
- SEO71
- Infrastructure88
- Reputation96
An outdated library with 5 known exploits — exactly what automated attacks scan for.
Our advantages
Security depth most checkers skip
Most checkers look for a padlock and call it a day. We go where attackers go — matching the exact library and CMS versions your website runs against known (OSV.dev, NVD, GitHub Advisory), and flagging what they'd exploit first.
- Known in your JS libraries & CMS version
- Missing or weak security headers (, , X-Frame-Options)
- Exposed sensitive files (.git, backups, logs)
- Weak TLS / certificate problems
- Blacklisting & Google Safe Browsing flags
- Insecure cookies & mixed content
jQuery 1.8.2 — 5 known CVEs
Fix: upgrade to 3.x
Why it matters
What a secure website gets you
Find the holes before an attacker does
See the exposed files, weak headers, and vulnerable libraries an attacker would exploit — and close them first.
Stay out of the next breach
Outdated software and known are how sites get defaced, ransomed, or leaked. Catch them before they're used against you.
Keep off the blacklists
A hacked or flagged website gets delisted by Google and blocked by email providers. Spot what puts you there before it does.
Earn customer trust
A secure website is table stakes for buyers. Prove yours won't leak their data.
Rank and load better, too
The same scan flags the performance and SEO issues quietly costing you traffic — health context alongside the security.
Coverage
What we scan for
The vulnerabilities and misconfigurations an attacker would look for — plus the health context that keeps you fast and findable.
Security
The core of the scan: the holes an attacker would find and exploit first.
- Known-vulnerable JavaScript libraries (CVEs)
- Outdated CMS core versions with known CVEs (WordPress, Joomla, Drupal…)
- Missing / weak security headers (, , X-Frame-Options)
- TLS & certificate problems (expiry, weak protocol)
- Exposed sensitive files (.git, backups) — with domain verification
- Insecure cookies, mixed content
- Email spoofing ( / )
- Blacklisting & Safe Browsing reputation
Active checks — port scanning and probing for exposed files — run only after you verify domain ownership.
We also check the rest
Performance
Core Web Vitals and delivery, measured via the PageSpeed Insights API.
SEO
The on-page fundamentals search engines expect to find.
Infrastructure
What powers the website — server, CDN, DNS, and TLS setup.
Reputation
Whether the domain is trusted, clean, and in good standing.
5
axes
32
checks per scan
Built on trusted, open data sources
- Google PageSpeed Insights
- Google Safe Browsing
- retire.js
- OSV.dev
- NVD
- GitHub Advisory
Where we fit
Between shallow health checkers and scary enterprise scanners
| Capability | Health checkers | Enterprise scanners | CheckWeb |
|---|---|---|---|
| Real vulnerability & detection | no | yes | yes |
| Finds exposed files & security misconfigs | no | yes | yes |
| Plain-English findings, no jargon | yes | no | yes |
| One readable 0–100 score | yes | no | yes |
| Free scan on any website (passive) | varies | no | yes |
| No sign-up, no email | varies | no | yes |
| Public shareable report + badge | no | no | yes |
| Continuous security monitoring | no | yes | yes |
…the depth you need, without the enterprise price tag or the sign-up wall.
The differentiator
Close the holes that matter first
We rank the holes by risk, so you close the most dangerous first — not a wall of 40 issues.
- 1Upgrade jQuery 1.8.2 → 3.x (5 known CVEs)+6
- 2Add missing security headers (, )+5
- 3Remove exposed .git directory+4
Ranked by severity × exposure — effort goes where the risk is.
Share your results
Every scan becomes a shareable public report
Each result gets its own clean, shareable page at chkweb.com/report/<domain>, plus an embeddable badge that links back to it.
Indexable by design
Reports are server-rendered pages that search engines and AI answer engines can read and cite.
A trust badge for your website
Embed the “Verified” badge to show visitors your security score at a glance — one click opens the full report behind it.
One-click sharing
Share to X or LinkedIn, or copy the link — the score travels with it.
Security score
Embeddable badge
<a href="https://chkweb.com/report/acme.com"><img
src="https://chkweb.com/badge/acme.com.svg"
alt="Website security checked by CheckWeb" /></a>Illustrative preview — run a scan to generate your own.
Pricing
Simple, honest pricing
Start free. The deep scan is free while we're in early access — a one-time audit after launch, or subscribe for continuous monitoring.
Quick scan
Available nowA passive security scan whenever you need one.
- On-demand passive scan
- Public shareable report
- Security score
- Core set of checks
Deep Audit
Early access$39 one-time after launch · no subscription
Actively scan your own verified site: exposed files, admin panels, ports, subdomains, per- breakdown, PDF. Free in early access — early adopters keep it free.
- Verify your domain, then active scan
- Exposed files, open ports, admin panels
- Full per- breakdown
- Prioritized fix list
- Full PDF report
Monitor
Coming soonContinuous security monitoring and alerts.
- Daily re-scan
- Alerts on new , cert expiry, blacklisting
- Watch SSL, domain & exposed files
- History & API access
Agency
Coming soonFor teams managing many websites.
- Everything in Monitor
- Multiple websites
- White-label reports & badge
- Team access
The free scan is passive and works on any site. Deep Audit and Monitor scan your own site actively (exposed files, ports, admin panels) — unlocked with a one-time domain verification.
Prices in USD. The free scan and the deep scan both work today — the deep scan is free while we're in early access. Monitoring plans arrive in a later phase; leave your email and we'll tell you the day they launch.
Transparency
How we score your security
A single number is only useful if you trust it. Our weighting is public — and tilted toward security.
Every check returns pass, warn, or fail and carries a weight. Each axis score is the weighted share of its checks; the overall score is a weighted sum of the five axes — and Security is the heaviest at 35%, because it's the highest risk to you if it fails. Critical security failures — a broken certificate, no HTTPS, a blacklisted domain — cap the score outright. The full methodology is published, no black box.
How each check is scored
Pass — Meets the best-practice bar for that check.
Warn — Works, but partial or below the ideal — worth improving.
Fail — Missing or actively harmful — a priority fix.
Draft weights — calibrated on real-world data and always published.
How the 100 points split across axes
Security 35%
Highest risk to the owner if it fails.
Performance 20%
Real impact on conversion and SEO, but rarely existential.
SEO 20%
Visibility and organic traffic.
Reputation 15%
Rare, but blacklisting is critical.
Infrastructure 10%
Mostly informational context.
Honest by design: hard limits
Some failures are too serious to average away. A website with a broken or untrusted certificate can't score above 50. No HTTPS at all caps you at 40. A blacklisted domain is capped too. That's why our scores can be genuinely low — and why a high CheckWeb score actually means something.
Would you trust a website that scores 42? Your visitors decide in seconds.
FAQ
Frequently asked questions
The short answers. More detail lands as we ship.
Can you scan my website for vulnerabilities?
Yes — that's the core of it. We detect known-vulnerable JavaScript libraries and CMS versions (matched to real ), missing security headers, TLS and certificate problems, exposed sensitive files, and blacklisting. Free, in plain English, no sign-up.
Is it safe — do you attack my website?
No. The free scan is strictly passive: we read publicly available data — response headers, the returned HTML, DNS, the TLS certificate, the library versions a page loads — exactly what any browser or search crawler sees. We never brute-force, send exploit payloads, or probe hidden paths. Deeper active checks (probing for exposed files, admin panels, or open ports) run only after you verify you own the domain.
Do you scan WordPress sites?
Yes. We fingerprint WordPress and its version, then flag the known affecting that core version as a security finding — with the count and severity — alongside your security headers, TLS, and blacklist status. This covers the WordPress core (and Joomla, Drupal, TYPO3, Magento, PrestaShop, 1C-Bitrix). Plugin- and theme-level coverage is on the way.
What can I see for free vs. after verifying my domain?
Everything passive is free on any website: the security score, vulnerable libraries and CMS versions, headers, TLS, blacklists. Active, intrusive checks — exposed files (.git, backups), open admin panels, port scans — run only on a domain you've verified as your own. That deep scan is live today and free while we're in early access (a one-time $39 audit after launch); continuous Monitor is still coming.
What counts as a vulnerability?
Anything an attacker could use against you: a JavaScript library or CMS version with a known , a missing or misconfigured security header, an expired or weak TLS certificate, an exposed sensitive file, insecure cookies or mixed content, or a domain that's been blacklisted. We report the finding and how to fix it — we don't try to exploit it.
Is the website security check free?
Yes. The public website security check and the score are free, with no sign-up. The Deep Audit — the active scan of your own verified site — is live and free during early access (a one-time $39 audit after launch, no subscription). Continuous Monitor ($19/mo) is coming later.
How is the security score calculated?
Each check returns pass, warn, or fail with a weight. Axis scores are weighted shares; the overall score is a weighted sum of the five axes — weighted toward Security (35%). Critical security failures (a broken certificate, no HTTPS, a blacklisted domain) cap the score outright. The full methodology is published in How we score.
What sources do you use for vulnerabilities?
Open data only — retire.js for front-end libraries, OSV.dev for packages, and NVD plus GitHub Advisory for CMS and server software. No proprietary databases.
How long does a scan take?
Most scans finish in 15–30 seconds. Performance data comes from the PageSpeed Insights API and is cached to stay fast.
How often should I scan my website?
Scan whenever you ship changes, update a plugin, or renew a certificate — new versions bring new . Security isn't a one-time check: a new vulnerability in your stack, a leaked file, or a blacklisting can land any day. Continuous monitoring (coming soon) re-scans for you and alerts you the moment something new appears.
Do you store my data?
The product is built privacy-first and GDPR-aligned. Public reports are indexable by design; anything tied to an account stays under your control.