Website Security Check

Enter a domain and see what your site tells the outside world. The check reads what the server sends back and nothing else.

What you get is what an outsider sees from your site at that moment, not what your configuration files say. If a CDN or a WAF sits in front, the values belong to that layer rather than to the origin. The result names what was detected in front of the site; the remediation it carries is the general one, which holds wherever the setting actually lives.

What is checked

  • HTTP security headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Cache-Control, the CORS configuration, cookie flags, the redirect from port 80, and server version disclosure.
  • SSL/TLS — the protocol versions still accepted, cipher suites, downgrade protection, renegotiation, compression, and the certificate itself: lifetime, chain, hostname coverage, signature algorithm and key size.
  • Post-quantum readiness — the key exchange the server actually negotiates, per address.

How to read the result

Findings fall into three groups. Needs fixing means it was measured and is there. Passed means it was measured and is not. Not assessed means there is no verdict. Nothing in that third group counts as a pass, and each row says why it is there.

After the result

Each finding carries its remediation — the setting to apply and the command to prove it landed — and says plainly when the layer you control cannot fix it and where to go instead.

If your organisation falls under the Website Security Standard B.E. 2568 (2025), this tool does not map its findings onto the clauses of that announcement. The self-assessment for that standard is a separate tool.

Frequently asked questions

Can I check a site I do not own?

You can. Its operator will see the connection from our scanner in their logs, so the check records who started it and keeps that for 90 days, as set out in our privacy policy. That is why the form asks you to confirm the site will be contacted from outside.

Why does a repeated check return the same result?

The scanner keeps the result for a given domain for 300 seconds. Inside that window the same request gets the same report back, and the page marks it as an earlier result with a countdown to when a fresh check is possible. There is no way to bypass that cache.

Which port is checked?

Only 443. A port typed after the domain is ignored and the check runs on 443 regardless. Port 80 is opened only to see whether it redirects to HTTPS.

Does this replace a penetration test?

No. This tool reads what the server answers without authenticating. Broken access control, business logic abuse and injection are found by hand after signing in, which is the scope of a penetration test.

logologo

INCOGNITO LAB CO., LTD.

38 Soi Petchakasem 30, Pak Khlong Phasi Charoen, Phasi Charoen, Bangkok 10160

©2026 Incognito Lab Co., Ltd. All rights reserved

Terms & ConditionsPrivacy Policy