Free security scanners and privacy tools
13 read-only tools. None of them need an account, none of them keep what you upload, and every result links to an explanation you can act on.

Which scanner do you need?
The 13 tools below answer different questions, and running the wrong one wastes your time. The short version: Scan a site when you control it and want to know what a stranger can see; scan your browser when you want to know what every site you visit can see about you; scan a file or a link when something arrived and you do not trust it.
You own the website
Start with the website vulnerability scanner. It covers headers, TLS, cookies, exposed files and outdated JavaScript in one pass, which makes it the fastest way to find out whether anything is actually wrong. If it is a WordPress site, the WordPress scanner adds plugin, theme and core version matching against published vulnerabilities. Once security is settled, the SEO and site health audit crawls the same site for what keeps it out of search results. The single-purpose tools — SSL/TLS, security headers, email spoofing and JavaScript libraries — are the website scan split into its parts, for when you are fixing one thing and want a fast re-check.
You want to know what your browser gives away
The browser security check runs inside the browser you are reading this in: Version currency, fingerprint uniqueness, cookie and storage behaviour, and which protections are switched on. The WebRTC leak test answers the narrower question of whether your VPN is actually hiding your address, and the extension analyzer tells you what an extension can read and change once installed.
Something arrived and you do not trust it
For an attachment, the file malware scanner analyses it in memory and never writes it to disk. For a link, the phishing URL checker opens it from our server instead of your browser and tells you where it actually ends up. If you have already typed a password somewhere you should not have, the password breach check tells you whether it is in the public breach corpora, without the password leaving your browser.
What they all have in common
Every tool is passive: Nothing is exploited, no form is submitted, no payload is sent. Every finding links to its own reference page explaining the test, the risk and the fix, and how we scan sets out exactly what happens on the wire. Free scans crawl up to 25 pages; a paid plan raises that to a full-site audit when a sample is not enough.
Websites
Point these at any public site you own or rely on.
Websites
Website Vulnerability Scanner
Headers, TLS, cookies, exposed files
Websites
SSL / TLS Checker
Certificate, expiry, protocols, ciphers
Websites
Security Headers Checker
CSP, HSTS, frame and MIME policies
Websites
Email Security Checker (SPF, DKIM, DMARC)
SPF, DKIM, DMARC and MX records
Websites
WordPress Vulnerability Scanner
Plugins, themes, core and known CVEs
Websites
JavaScript Library Vulnerability Scanner
Outdated libraries with known CVEs
Websites
SEO & Site Health Audit
Crawl, titles, links, speed, structured data
Browsers
These run inside the browser you are using right now.
Files
Analysed in memory, never written to disk.
Privacy
Check a link or a password without giving anything away.
Not sure what a result means?
Every check has its own reference page with the test, the risk and the fix.