A website security scanner that explains itself
Find exposed files, missing security headers, weak cookie settings, mixed content, injected-malware indicators, email spoofing gaps (SPF and DMARC) and version leaks on websites you own - with the evidence, the risk and the fix for every finding.
Every finding comes with evidence and a fix
Each scan returns a clear list of checks with their status, the evidence Webforta saw, why it matters and exactly how to remediate - grouped by severity so you fix the important things first.
Try the free header checkTransport & certificates
HTTPS availability, HTTP-to-HTTPS redirects, HSTS policy and certificate expiry from Certificate Transparency logs.
Headers & cookies
Content-Security-Policy, clickjacking protection, MIME sniffing, referrer and permissions policies, permissive CORS, cookie flags.
Exposed files
Signature-confirmed checks for .git, .env, .htpasswd, SVN metadata, SQL dumps, config backups, phpinfo and server-status pages.
Technology exposure
Identifies WordPress, Drupal, Joomla, Shopify and more, and flags version banners that help attackers.
Mixed content
Scripts, stylesheets, frames, media and forms loaded or submitted over plain HTTP on HTTPS pages.
Scheduled scans
Weekly (Pro) or daily (Business) scans with alerts when new high-severity findings appear.
Built to be gentle with your site
- About 20 read-only GET requests per scan, at most 4 at a time.
- No exploits, payloads, password guessing or crawling.
- Only domains you verify with DNS. Redirects off your site are not followed.
- Identifiable user agent: WebfortaScanner/1.0.
Check any site's security headers
This public check makes one HTTPS request to the homepage - the same as a browser visit - and reviews the security headers in the response. It is not a security assessment and does not look for exposed files or vulnerabilities. Results are not stored.
See what your website shows attackers
Start a 14-day trial, verify a domain and run your first scan in about ten minutes. No card required.