Skip to content

Understand your website's security.

Find out what it exposes, what matters, and what to ask your team to improve.

2 scans per site each day. No account. Nothing is exploited.

See an example report

example-bakery.com

Example reading

Observed posture index

Needs improvement

Areas evaluated 5/5

  • HTTPS38
  • Headers54
  • Email63
  • DNS92
  • Web83

Observed posture index

Needs improvement

5 areas evaluated. The weakest is HTTPS and TLS, at 38 out of 100.

HighHTTPS and TLS

An outdated TLS version is still enabled

What was observed

protocol: TLS 1.0, TLS 1.1

HTTPS and TLS · An outdated TLS version is still enabled

What to ask for

Ask them to accept TLS 1.2 and TLS 1.3 only, and to remove TLS 1.0 and 1.1.

Example data, produced by the same engine a real check runs. Your own check takes two to four minutes.

What a reading looks at

Five areas, each a different kind of signal your site already publishes to anyone who asks. Choose one to see what is checked and what a finding says.

HTTPS and TLS

The protocol versions your server still accepts, the strength of its cipher suites, and whether the certificate chain a browser has to trust is complete and current.

What the example found

Highexample-bakery.comA weak cipher suite is offeredAmong the encryption options your server offers, at least one is considered broken or too weak to rely on. A connection that ends up using it is not meaningfully protected.

What to ask for

Ask them to adopt the Mozilla intermediate cipher list and remove everything outside it.

Example data. The wording is the same wording a real report uses.See the full example report

From what was seen to what to do

Every finding arrives in three parts. This is the real catalog wording for the missing DMARC record in the example above.

High

No DMARC record was found

_dmarc TXTabsentRFC 7489

No TXT record beginning with v=DMARC1 was published at _dmarc under the domain.

What you get back

One page. The index with the coverage it was computed over, the findings that warrant action first, and every area with its own reading.

example-bakery.comExample report
DNS hygiene92 of 100
Good2 findings
Email domain security63 of 100
Needs improvement3 findings
HTTPS and TLS38 of 100
Weak3 findings
Public web configuration83 of 100
Needs improvement3 findings
Security headers54 of 100
Weak5 findings
  • What matters

    Up to three actions, worst first, each one linked to the finding it came from and written as a sentence you can forward.

  • What was checked

    Five areas, each with its own reading on the same scale as the index. An area that could not be evaluated says so instead of scoring zero.

  • What the number is

    A weighted index over the areas that were evaluated, with its coverage next to it. Not a percentage, and not a grade.

Open the full example

For the people who keep a website running

The same reading, read three different ways. What you do with it depends on who you are.

  • Businesses with a website

    Find out what is worth looking at, even without a security team. The result names what was seen, what it means, and the sentence to send to whoever built the site.

    Check my site
  • Online shops

    Read the public signals of your site and of the domain your customers see in their inbox. Whether someone can send an invoice in your name is a DNS record, and it is one of the five areas.

    See what is checked
  • Agencies and developers

    Bring a first reading to the conversation, then open the detail to act on it. Every finding carries its evidence, its severity and its confidence separately.

    Open an example report

Why choose SiteGuardia

A first look at your website that you can understand and turn into actions.

  • Every finding arrives in three parts: what was observed, what it means in plain language, and what to ask your technical team for. The middle part is the one that lets you decide whether to act without already knowing the subject.

    A finding, and the one that comes first

What it refuses to do

The boundary is the product. These are not features waiting to be built; they are things SiteGuardia will not do to a site it has no authorisation for.

SiteGuardia Free performs automated, non-destructive checks and cannot prove that a website is secure or free of vulnerabilities. It does not replace a professional penetration test.

  • No exploitation of any finding
  • No password guessing or credential testing
  • No injection payloads or fuzzing
  • No load testing or denial of service
  • No authentication, and no form submission
  • No scanning of private or internal addresses

Why serious findings stay hidden

If a check finds something genuinely serious on a domain nobody has proven they own, the technical evidence is classified and dropped before it is written down. The database never holds it, the API never returns it, and there is nothing in the page for a browser to reveal.

CriticalDetails withheldThe finding still counts against the score. Withholding the detail does not withhold the consequence.

Questions

What people ask before they type a domain in. If yours is not here, the methodology page goes further.

Check your own site

Check for free