How we assess website security
The check runs externally and passively — nothing is installed on your website, nothing is hacked, and no data is changed. We only look at what the server itself makes public. The scoring is transparent: we start at 100 points and subtract for every issue we find (at most 10 points per issue).
We keep it simple: results are presented so a website owner can understand them — not just a CISO or developers. This is a free initial overview. For those seeking maximum security and in-depth analysis, we perform professional full-scope security audits.
🔒TLS / SSL certificate
- No SSL, or the check failed −10
- Certificate has expired −10
- Expires in < 14 days / < 30 days −10 / −5
- Untrusted certificate chain −10
- Weak RSA key (< 2048 bits) −10
- ECDSA P-256/384/521 — strong, no penalty 0
🛡️Security headers (HTTP headers)
- HSTS (Strict-Transport-Security) −10
- Content-Security-Policy (CSP) −8
- X-Frame-Options (clickjacking) −6
- X-Content-Type-Options −4
- Referrer-Policy −3
- Server reveals software versions −5
🍪Cookies
- Cookies without Secure / HttpOnly flags −7
🌐DNS
- DNSSEC not enabled −5
🧩Software (WordPress / PHP)
- WordPress badly outdated (large gap) −10
- WordPress outdated (minor version) −8
- PHP no longer supported (end of life) −10
- readme.html reveals the WordPress version −3
- Components with a disclosed version → for CVE review info
✉️Email protection (extended scan)
- No SPF record −8
- No DMARC record −6
- Weak DMARC (p=none) −2
- No DKIM signature found −6
⚠️Reputation
- Domain in a phishing database −10
- Blocked by security filters (malware) −10
- Blocked by content filters −2
📡IP reputation (DNSBL)
- IP on 2+ spam/abuse lists (Spamhaus, SpamCop…) −10
- IP on 1 list −6
- IP clean on reputation lists 0
🔎AbuseIPDB (advanced scan only)
- Abuse score ≥ 75/100 −10
- Score 25–74 −6
- Score 1–24 −2
- Score 0 — clean 0
🏅Grades
🎚️Scan types
- Simple — the technical surface: TLS / SSL, security headers, cookies, DNSSEC, version disclosure, software (WordPress / PHP) and CVEs, reputation (phishing / blocklists) and IP reputation (DNSBL).
- Extended — everything in Simple plus email protection: SPF, DKIM and DMARC.
- Advanced — everything in Extended plus AbuseIPDB IP-reputation enrichment, and lets you check a specific URL — a subdomain or a path, not just the main domain.
Each report is stamped with its type (simple / extended / advanced), date/time, GMT (UTC) and template version.
What you get in the report
An overall score (0–100), a list of the issues found with an explanation of what each one means and how to fix it — in plain language, not for an IT specialist. You also get a list of the things that are fine, plus a summary (IP, SSL issuer, server, WordPress / PHP versions). Every report shows the date/time, GMT (UTC), template version and scan type (simple / extended / advanced). The full report can be opened as a PDF and received by email.
Run a free check →⚠️ This is only a simple online test
This free test shows only the publicly visible, most common issues and is meant for the website owner — not an IT specialist, DevOps or CISO. A full security audit is a paid service and is far more thorough: deeper (penetration) testing, internal analysis, manual checking and tailored recommendations. For an audit: pagalba@parescius.lt.
The check does not change or load your website. The same domain can be re-checked once per day. For deeper (penetration) testing or fixing issues: pagalba@parescius.lt