Complimentary website security check

How secure is your website from the outside?

Get a complimentary baseline website security check from OSKY.

A website can look perfectly normal while still exposing information, files or configuration issues that increase its security risk.

Check my website No website login or backend access is required.
Website Security Check Illustration
External, non-invasive checks
Practical recommendations
No obligation to engage OSKY

A practical starting point

What we check

OSKY’s complimentary baseline website security check provides organisations with a quick external review of several important security controls and common exposures. Our baseline check looks at security issues that can be assessed externally from your website’s public-facing environment.

01 / Connection

HTTPS and TLS security

We check whether your website is using HTTPS correctly and review several important aspects of its TLS configuration, including:

  • whether HTTP traffic redirects to HTTPS
  • the validity and expiry of your SSL/TLS certificate
  • whether outdated TLS 1.0 and TLS 1.1 protocols are disabled
  • whether HTTP Strict Transport Security (HSTS) is implemented
02 / Protection

Security headers

Security headers help browsers protect visitors from certain types of attacks. We check for common protections including:

  • Content Security Policy (CSP)
  • X-Frame-Options or equivalent frame-ancestors protection
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy
03 / Visibility

Information leakage

Websites can sometimes reveal technical information that makes it easier for attackers to understand the technology running underneath them. We check for publicly visible information such as:

  • web server or software version information
  • X-Powered-By headers
  • WordPress generator information
  • publicly accessible WordPress readme files
04 / Exposure

Exposed files and directories

We perform a small number of non-invasive checks for files or directories that should not normally be publicly accessible, including:

  • environment configuration files
  • exposed Git information
  • WordPress debug logs
  • PHP information files
  • backup WordPress configuration files
  • directory listing within WordPress upload directories

We only flag an exposure where a request returns publicly accessible content consistent with the file or directory being tested.

Clarity, not complexity

What you'll receive

If we identify potential issues, we’ll provide you with a straightforward summary explaining:

What we found

Why it may matter

The level of attention it deserves

Recommended next steps

Our aim is to give you a practical starting point for understanding your website’s externally visible security posture.

There is no obligation to engage OSKY for further work.

No backend access required

This baseline check is performed entirely from outside your website. You do not need to provide:

  • WordPress or CMS credentials
  • Hosting credentials
  • Server access
  • Administrator accounts
  • Database access

This makes it a simple way to identify some of the security issues that are visible from the public internet.

Three simple steps

How it works

01

Tell us where to look

Submit your website URL and a few details using the short form below.

02

We check your website

Once we receive your request, the OSKY team will review the website and carry out the applicable baseline checks.

03

Understand your next steps

If we identify anything that warrants attention, we’ll explain what we found and recommend appropriate next steps.

In some cases, an issue may require further investigation or access to the website environment before its significance can be determined.

Start with a baseline

Request your complimentary website security check

Tell us where to look and we’ll take it from there.

No login or backend access required.

No login or backend access required.

A few useful answers

Frequently asked questions

Is the website security check complimentary?

Yes. This baseline website security check is complimentary, and there is no obligation to engage OSKY for further work.

Do you need access to our website?

No. The baseline check is performed entirely from outside your website. You do not need to provide CMS credentials, hosting credentials, server access, administrator accounts or database access.

Is this a comprehensive security audit?

No. The complimentary check is intentionally limited to selected issues that can be identified externally without administrative access. It is not a penetration test, vulnerability assessment or certification that a website is secure.

Will the checks change our website?

OSKY performs only the external checks described above and does not attempt to exploit identified vulnerabilities, alter website content or gain unauthorised access to systems.

What happens if you find an issue?

If we identify anything that warrants attention, we’ll explain what we found and recommend appropriate next steps. In some cases, an issue may require further investigation or access to the website environment before its significance can be determined.

When you need to go further

Need a deeper security assessment?

Our complimentary check is intentionally limited to issues that can be identified externally without administrative access.

For organisations requiring a more comprehensive assessment, OSKY can undertake a deeper website security audit that examines the website environment, configuration, software and security controls in greater detail.

This may include appropriate access to the CMS, hosting environment or other systems depending on the scope of the assessment.

Talk to OSKY about a comprehensive website security audit

Important information

The complimentary baseline website security check is designed to identify selected security issues that are observable from a website’s public-facing environment at the time of testing. It is not a penetration test, vulnerability assessment or certification that a website is secure. Because no authenticated or backend access is used, vulnerabilities may exist that cannot be detected through these checks. OSKY performs only the external checks described above and does not attempt to exploit identified vulnerabilities, alter website content or gain unauthorised access to systems.