HTTPS and TLS security
We check whether your website is using HTTPS correctly and review several important aspects of its TLS configuration, including:
- whether HTTP traffic redirects to HTTPS
- the validity and expiry of your SSL/TLS certificate
- whether outdated TLS 1.0 and TLS 1.1 protocols are disabled
- whether HTTP Strict Transport Security (HSTS) is implemented
Security headers
Security headers help browsers protect visitors from certain types of attacks. We check for common protections including:
- Content Security Policy (CSP)
- X-Frame-Options or equivalent frame-ancestors protection
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
Information leakage
Websites can sometimes reveal technical information that makes it easier for attackers to understand the technology running underneath them. We check for publicly visible information such as:
- web server or software version information
- X-Powered-By headers
- WordPress generator information
- publicly accessible WordPress readme files
Exposed files and directories
We perform a small number of non-invasive checks for files or directories that should not normally be publicly accessible, including:
- environment configuration files
- exposed Git information
- WordPress debug logs
- PHP information files
- backup WordPress configuration files
- directory listing within WordPress upload directories
We only flag an exposure where a request returns publicly accessible content consistent with the file or directory being tested.