The basics browsers expect
Every visitor’s browser checks these settings before it trusts your site. Missing ones mean warnings for visitors and easy wins for attackers.
Check your secure connection and the browser protections your website provides.
Why it matters
Every visitor’s browser checks these settings before it trusts your site. Missing ones mean warnings for visitors and easy wins for attackers.
None of these settings shows on the page, so they are easily forgotten when a site is built. They are also quick to add.
A handful of one-line settings limits what an attacker can do if they ever find another way in. This report tells you which ones you have.
Common questions
The settings your website sends to every visitor’s browser: whether the connection is secure and stays secure, and the instructions that limit what scripts can run, whether other sites can embed your pages, and what information is shared when someone follows a link.
Yes. We only read what any visitor’s browser already receives. We do not sign in, submit anything or change anything. Please only check websites you own or look after.
It is rarely an emergency, but it is a sign the site is not being looked after. Most of these settings take a website provider a few minutes to add and cost nothing.
Usually because the website blocked automated visitors, or did not answer in time. The report says which, and what would let us check it. A check we could not complete is never counted against you.
It means the basics are in place. This check does not test every page, sign in, or look for faults in the site’s own code, so treat a good result as a solid start rather than a certificate.