Free · Passive · Plain English

Is your website leaving the door open?

A free security check for small-business websites. In about 15 seconds you get the common security gaps, what each one means, and how to fix it.

Enter a domain like yourbusiness.com

Scans are passive: we load your public home page, read its headers and certificate, look up public DNS records, and request a few well-known file paths, like a normal visitor. No logins, no attack traffic. Only check sites you own or are authorized to test.

Want to see one first?

What we check

Common gaps that are easy to overlook and usually quick to fix. Every finding shows the actual evidence we saw.

HTTPS & certificate

HTTPS works, http:// redirects to it, the certificate is trusted and not about to expire, modern TLS, no insecure mixed content.

Security headers

HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

Email spoofing protection

SPF, DMARC policy, and DKIM on common selectors, so scammers can't easily send fake emails "from" your business.

Information leaks

Software version banners, public folder listings, and a short list of files that should never be public, like .env and .git.

Cookies

Whether cookies use the Secure, HttpOnly, and SameSite flags that protect logged-in sessions.

How it works

No sign-up and nothing to install.

  1. Enter your websiteConfirm it's yours (or you have permission), then start the check.
  2. We look, we don't pokePlain code reads what any visitor could see: headers, certificate, public DNS, and a few well-known paths.
  3. Get a plain-English reportA 0–100 score with the math shown, an A–F grade, and what each issue means and how to fix it.

Want the gaps fixed?

SiteSafeCheck is built by Nick Castro, a web developer who fixes the common website security gaps for small businesses. He's upfront about what he does and doesn't do.

One-time fix · $250–$500

Nick fixes the gaps your report found:

  • Security headers
  • HTTPS / SSL setup and redirects
  • SPF, DKIM and DMARC email protection
  • Hiding software version banners
  • Cookie security flags

Monthly re-scan & watch · $50–$100/mo

Nick re-runs the check every month and tells you in plain English what changed, including certificates getting close to expiring.

Part of a website package

Getting a new site or a refresh from Nick? These protections can be bundled in.

Referred out

Penetration testing, code audits, malware or breach cleanup, server repairs, and exposed sensitive files go to a specialist. Nick can point you to one.

Call (708) 250-1040Text NickEmail nickcastro1520@gmail.com

Questions

Is SiteSafeCheck really free?

Yes. There's no sign-up and no card. Fair-use limits keep it free for everyone.

Is the scan safe to run on my website?

Yes. It's passive: it loads your home page, reads the response headers and certificate, looks up public DNS records, and requests a short list of well-known file paths, about what a normal visitor or search engine does. It never logs in, submits forms, or sends attack traffic. Only check sites you own or have permission to test.

Does a good grade mean my site is secure?

No. A passive check only sees what's publicly visible. A good grade means the common configuration gaps are covered. It can't prove a site is secure or find problems inside your code, plugins, or server.

How is the score calculated?

Every report starts at 100. Each failed check subtracts 15 (high), 8 (medium), or 3 (low) points, and warnings subtract about half. Any high-severity failure caps the score at 69. 90+ is an A, 80+ a B, 70+ a C, 60+ a D, and below 60 an F.

What does it store?

The domain you check and its report are cached for about 10 minutes so repeat checks are instant. A hashed version of your IP address is kept for about a day for rate limits. The domain and its findings (nothing about you) are sent to Google's Gemini API to write the plain-English explanations. Nothing is sold. Details are on the privacy page.

Can you fix what the report finds?

Nick Castro can fix the common configuration gaps: security headers, HTTPS/SSL setup, SPF, DKIM and DMARC email protection, hiding version banners, and cookie flags. A one-time fix is $250 to $500, and a monthly re-scan and watch is $50 to $100 a month. Exposed files, penetration testing, code audits, and breach or malware cleanup are referred to specialists.