Trust at a glance
A composite trust score from real captured signals, HTTPS, headers and configuration, so you see risk before it costs you.
A bounded scorecard for captured site trust signals, headers and supported external probes.
Site Trust & Security scores your site's HTTP trust signals and security headers from a real crawl, and runs an automated pentest for exposed database ports and leaked backup files.
Automated pentest (exposed ports & backup leaks) on Pro+
Why it is useful
Most security tools either overwhelm you with raw scanner noise or quietly guess at gaps they never actually measured, and both leave you unable to say which findings are real. You need a trust picture built only from what your site truly exposes to any visitor, with a clear, specific fix attached to every finding.
A composite trust score from real captured signals, HTTPS, headers and configuration, so you see risk before it costs you.
Detect exposed database ports and leaked backup files (.sql dumps, .env, .git) that quietly leak your data.
HSTS, CSP and X-Frame-Options coverage graded, with the exact fix for each gap.
Data and evidence
Site Trust reads what your own pages return: HTTPS coverage across every crawled URL, whether HTTP redirects to HTTPS, the six security response headers with CSP strength graded, and mixed content on secure pages. An exposure scan that could affect a live host runs only after domain ownership is verified.
Crawl plus verified-domain probes
Weighted trust criteria
Evidence-linked security queue
Exposure scanning runs only for verified domains; a reachable path is a review finding, not proof that sensitive data was disclosed.
Core capabilities
You get a weighted trust score built from measured factors, a per-header scorecard that names which header is missing or weak on which pages, mixed-content findings resolved to URLs, and an ownership-gated exposure scan for the checks that need permission before they are run.
A single 0-100 trust score is computed across every crawled HTML page from four weighted factors: HTTPS coverage, security-header strength, freedom from mixed content, and Cache-Control hygiene. When there are no crawled pages to observe, the score is reported as insufficient rather than a fabricated zero. Each factor shows its own coverage percentage and the exact page counts behind it.
Coverage is scored for the six standard response headers: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. CSP is credited by policy strength, so a real default-src/script-src policy earns full credit while an upgrade-insecure-requests-only header is flagged as weak. A header stored as empty means the site genuinely never sent it, which is treated as a true missing finding, not a capture gap.
For a domain you have verified you own, an active scan probes for exposed files, checks the live TLS certificate, and detects publicly open ports. It looks for leaks such as .env, .git/config, database dumps and config backups, reads the certificate issuer and days-to-expiry, and flags disclosed server banners or X-Powered-By values. For anyone else the domain stays unverified, so these signals read as not checked and never dock the score with a failure that was never measured.
How the work moves
Crawl the site, let the factors be scored, verify ownership when you want the deeper scan, then fix each finding against the page it came from. The score is recomputed from the next crawl, so a fix is confirmed by measurement instead of being assumed once the change is deployed.
Every HTML page's HTTPS status, response headers and mixed-content signals are captured during the crawl.
HTTPS coverage, header strength, mixed content and cache hygiene are combined into one weighted trust score.
For a domain you have verified, an active scan adds live TLS, open-port and exposed-file checks.
Every issue arrives as an atom with evidence and a copy-ready server-config fix.
Built around real work
Get one honest trust score and a prioritized list of the exact headers and exposures to fix first.
Run a repeatable HTTP-level security audit on a client site and hand over evidence-backed remediation steps.
Confirm that HTTPS is enforced, security headers are set, and no config or backup files are publicly reachable before launch.
Connected outcomes
Resources
Written by the team that built it, and free to read without an account.
Step-by-step walkthroughs, five minutes each.
What the terms on this page actually mean.
Run the idea on a real URL, no account needed.
Connected products
Frequently asked questions
Clear answers about data, availability and how the product fits into the wider workflow.
No. All checks are HTTP-level and network-level; the scan detects publicly open ports but never logs in or touches the filesystem.
The scorecard reads the value actually captured on each page; an empty value means that page did not send the header in its response.
It is reported as not checked, not as an invalid certificate, so a connection we could not complete never fabricates a failure.
The exposed-file, TLS and port scan only runs once you have verified ownership of the domain, which keeps active probing to sites you control.
Trust & Experience
Start with a real project, keep unavailable data visible and follow the connected workflow when the result is ready for action.