1. Nguồn
One live TLS handshake, HTTPS response, and seven selected TCP-port probes. The result identifies where its evidence came from.
Audit website security posture, TLS/SSL certificates, HTTP security headers, and open ports with instant live evidence. Free online security check.
Gửi một URL công khai, tên miền, hoặc từ khóa. Novaverb sẽ chỉ hiển thị bằng chứng mà công cụ này thực sự có thể lấy hoặc đo lường.
This check proves what a site presents to any visitor at the network edge: the live TLS certificate, the negotiated protocol version and cipher, which of the six OWASP baseline response headers are present, the disclosed Server banner and a small set of exposed common ports. It cannot prove that a site is secure, because no external probe can see application logic, patch level or access control.
One live TLS handshake, HTTPS response, and seven selected TCP-port probes. The result identifies where its evidence came from.
This is a limited, non-intrusive external probe - not a vulnerability scan or penetration test. It cannot prove that a website is secure or compromised.
Sử dụng phát hiện để xác minh một vấn đề, sau đó kết nối một không gian làm việc khi bạn cần lịch sử, giám sát hoặc phân tích toàn bộ trang web.
Novaverb thực hiện một kiểm tra bên ngoài hạn chế của một trang web công khai: nó xác minh chứng chỉ TLS được trình bày trên cổng 443, đọc các tiêu đề phản hồi HTTPS đã chọn, ghi chú các định danh máy chủ hiển thị, và cố gắng kết nối TCP đến bảy cổng dịch vụ thường được xem xét. Đầu ra là bằng chứng tại thời điểm - không phải quét lỗ hổng đầy đủ, quét phần mềm độc hại hoặc kiểm tra xâm nhập.
Trình kiểm tra chỉ chấp nhận tên máy chủ có thể định tuyến công khai và từ chối các mục tiêu mạng riêng tư hoặc đã được dự trữ.
Nó mở một kết nối TLS trực tiếp, xác minh tên miền và chuỗi chứng chỉ, sau đó ghi lại phiên bản và cipher đã thương lượng.
Nó yêu cầu trang chủ HTTPS và ghi lại sáu tiêu đề chính sách được chọn cùng với các định danh máy chủ hiển thị.
Nó cố gắng kết nối TCP đến 21, 22, 23, 25, 3306, 5432 và 6379. Một phản hồi có nghĩa là có thể truy cập, không phải là lỗ hổng.
Trang phân biệt quan sát và diễn giải và liên kết đến các thông số chính được sử dụng để giải thích mỗi tín hiệu.
Không. Trang này cố ý không tạo ra một điểm số an ninh chung. Nó báo cáo một tập hợp nhỏ các tín hiệu cấu hình có thể quan sát từ bên ngoài.
Không. Một kết nối TCP thành công chỉ cho thấy rằng có điều gì đó đã trả lời từ vị trí kiểm tra này. Rủi ro phụ thuộc vào dịch vụ, xác thực, vá lỗi, chính sách tiếp xúc và cấu hình.
Không. Sự hiện diện chỉ là kiểm tra đầu tiên. Giá trị có thể không hợp lệ về mặt cú pháp, quá cho phép, không đúng phạm vi hoặc không tương thích với ứng dụng.
Nếu yêu cầu HTTPS hết thời gian hoặc không thể truy xuất tiêu đề phản hồi, không có bằng chứng nào để gọi một tiêu đề là thiếu. Trình kiểm tra giữ sự phân biệt đó rõ ràng.
Không. Nó không gửi bất kỳ tải tấn công nào và không kiểm tra mã ứng dụng, cơ sở dữ liệu, tệp, tài khoản hoặc phụ thuộc.
TLS bảo vệ xác thực, tính bảo mật và tính toàn vẹn trong quá trình truyền. Nó không sửa mã dễ bị tổn thương, mật khẩu yếu, tài khoản bị đánh cắp hoặc cấu hình máy chủ không an toàn.
Đây là một phép thử bên ngoài không xâm lấn về TLS, tiêu đề phản hồi và một vài cổng phổ biến - không phải là quét lỗ hổng hoặc kiểm tra xâm nhập, và nó không thể chứng minh một trang web là an toàn.
Submit the public domain or any URL on it. The host is what matters, so scheme, www and path are normalised away before the handshake. A private or internal host is refused by design, and a result from a staging domain says nothing about production, because the certificate and header configuration are usually different systems.
yourdomain.comBất kỳ trang web công khai nào bạn sở hữu hoặc được ủy quyền để kiểm tra. http hoặc https, có hoặc không có www, một miền trống hoặc một đường dẫn đầy đủ - chúng tôi chuẩn hóa cho bạn.https://www.yourdomain.comProbe chỉ đọc những gì bất kỳ trình duyệt nào có thể thấy - không đăng nhập, không khai thác.Expecting a penetration testĐây là một probe bên ngoài không xâm nhập, không phải quét khai thác - nó không thể chứng minh một trang web là an toàn hoặc bị xâm phạm.admin.internal.corpCác máy chủ nội bộ hoặc riêng tư bị chặn. Chỉ các trang web công khai có thể giải quyết, được ủy quyền mới được kiểm tra.A live TLS handshake is opened and the certificate, negotiated version and cipher are read from it. The response headers are then inspected for HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy, the Server banner is noted, and a small set of common TCP ports is probed. Each signal is reported present, missing or weak.
The bar is set by published specifications, not an in-house score. RFC 8446 defines TLS 1.3, RFC 6797 defines HSTS, W3C CSP Level 3 defines Content-Security-Policy, and the OWASP Secure Headers project defines the baseline header set this check counts. Each header is judged against its own specification, so a pass means the specification is met.
Đọc phiên bản TLS đã thương lượng và chứng chỉ từ một lần bắt tay trực tiếp.
Đọc thông số kỹ thuậtPhát hiện tiêu đề Strict-Transport-Security của bạn và việc tăng cường của nó (max-age, includeSubDomains, preload).
Đọc thông số kỹ thuậtKiểm tra xem tiêu đề Content-Security-Policy có hiện diện và hạn chế script-src / default-src hay không.
Đọc thông số kỹ thuậtSo sánh các tiêu đề phản hồi của bạn với tiêu chuẩn OWASP của sáu tiêu đề bảo mật.
Đọc thông số kỹ thuậtIt runs a limited external probe of a public site: the TLS certificate, six security response headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy), the disclosed Server header, and seven common TCP ports.
No. It is a non-intrusive external probe that reads publicly visible signals only. It does not exploit anything, log in, or scan for CVEs, and it cannot prove a site is secure or that it is compromised.
Add the missing headers at your web server or CDN edge. Start with HSTS (Strict-Transport-Security), X-Content-Type-Options: nosniff, and a Referrer-Policy, then build a Content-Security-Policy, which is the hardest to configure safely.
HSTS (HTTP Strict-Transport-Security) is a response header telling browsers to always use HTTPS for your domain, preventing protocol-downgrade and cookie-hijacking attacks. A good baseline is max-age of at least 31536000 seconds (one year).
The OWASP Secure Headers baseline includes Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. The checker reports which of these six are present, missing, or misconfigured.
A detailed Server header (naming software and version) hands attackers a version fingerprint to match against known exploits. Suppressing or genericising it via server config removes an easy reconnaissance signal, though it is hardening, not a real fix.
A certificate check alone confirms encryption is valid and unexpired. This scan reads the certificate too, but adds response headers, the Server banner, and open ports, giving a broader external hardening snapshot rather than a single trust signal.
Ideally only the ports you intend to serve publicly (typically 443, and 80 for redirects) respond. Exposed database, remote-desktop, or admin ports on a public host are worth reviewing and firewalling off.
No. A clean external probe means these specific public signals look healthy. It says nothing about application logic, authentication, unpatched software, or server-side vulnerabilities, so treat it as one input, not a certificate of security.
Google favours HTTPS, and browsers flag insecure pages, hurting trust and click-through. Valid TLS and hardening headers protect users from tampering and mixed-content warnings, supporting the safe-browsing signals that underpin sustainable search visibility.