Website Trust & Security Checker

One page. Real findings. Free.

Check a homepage or important landing page. See what looks strong, what needs work, and what to improve.

One page free · No card · Read-only

Trust signals

Look for proof, contact paths, headings, and next-step links or buttons where they are expected.

Public-facing security

Review HTTPS, browser protections, cookies, forms, and other observable security settings.

The next useful change

Open the finding, check the evidence on the named page, and use its recommendation.

What is covered

Inside the security scan

Every reviewed page gets the same set of checks. Open a category to see the details.

Connection and certificate

How the page connects, the certificate it presents, and where redirects lead.

  • HTTPS connection
  • Website security certificate
  • Certificate dates
  • Negotiated TLS version
  • Certificate public-key strength
  • Certificate signature algorithm
  • Send HTTP visitors to HTTPS
  • Insecure redirect
Browser protections

The settings that guide how a browser handles scripts, content, and other websites.

  • Protection against unapproved scripts
  • Script-protection settings
  • Embedded-object restriction
  • Base-address policy
  • Form-destination policy
  • Keep visitors on HTTPS
  • HTTPS protection for subdomains
  • Protection against page embedding
  • File-type protection
  • Referrer privacy setting
  • Browser feature permissions
  • Window isolation setting
  • Resource-sharing boundary
  • Cross-origin embedder setting
  • Visible software version details
  • Outdated script-protection setting
Cookie settings

The security settings on cookies returned with the page.

  • Cookie Secure setting
  • Cookie HttpOnly setting
  • Cookie SameSite setting
  • Cross-site cookie transport
  • Cookie security prefixes
Page content and destinations

Visible resources, downloads, forms, frames, and links in the page.

  • Insecure active page resources
  • Insecure media resources
  • Insecure download links
  • Form destination security
  • Sensitive form handling
  • Integrity coverage for third-party files
  • Integrity metadata format
  • Automatic redirect security
  • Forms sent to another website
  • Third-party frame restrictions
  • New-tab link isolation

Some checks will not apply to a particular page. If evidence is missing, the report says so. Results reflect only what these checks observed at scan time; they do not establish that the whole site is safe.

Additional context, when available

Paid reports may include a separate Google Web Risk result for the starting address. Browser observations and Google PageSpeed Insights results can add context too. Availability depends on the service returning useful evidence.

Before you scan

What the scan can—and can’t—see

Which page will it scan?

The exact public page you enter. Use a page you own, manage, or have permission to review.

Can I scan more of the site?

Yes. The paid report reviews up to 12 relevant public pages and groups repeated findings with their affected pages.

Will the scan change my website?

No. It is read-only: no logins, form submissions, or attempted attacks. It is not a penetration test.

Where does Google Web Risk fit?

When available, paid reports may ask Google Web Risk about the exact page address you entered. It adds a separate threat-list result and cannot guarantee that the website or business is safe. The free scan does not use Google Web Risk.

What happens when a check needs another look?

Read the availability note or open any recorded details. “Not verified” means there was not enough evidence for a conclusion—not a confirmed problem.

Check your website

Try the page that matters most.

Start with your homepage, service page, or pricing page.