PUBLIC HTTPS · BOUNDED INSPECTION

You shipped it.
What’s showing?

See the public signals your site sends—and which ones deserve a closer look.

Public HTTPS · No saved reports.

Outside observations.
Useful context. No dramatic verdicts.

SHIP WITH CURIOSITY.

Your website has a public side.
Get to know it.

A LITTLE VISIBILITY GOES A LONG WAY

Less mystery.
More perspective.

Your site tells the browser more than what’s on the page. We help you read between those lines.

01 /

Drop your URL.

A deployed, public HTTPS website. No account, setup, or access to your code.

02 /

We look from outside.

Bounded, read-only requests to your origin and explicitly referenced browser files.

03 /

Get the context.

See what’s observable, why it matters, and where a closer review could help.

INTENTIONALLY FOCUSED

Small scope.
Clear boundaries.

Public responses can tell you something. They can’t tell you everything.

THE OUTSIDE VIEW · LIMITED BY DESIGN

What we look at

  • HTTPS & transport policy
  • Content security policy
  • Content type & framing headers
  • Cookie attributes, when present
  • Bounded initial HTML, referenced JavaScript and one source map

Where we draw the line

No crawling, sign-ins, form submissions, or exploitation. The score covers completed public checks, never overall security.

Reports stay in browser memory. A missing header calls for review, not a verdict on your website.