Powered by vErtex Security Engine

How secure is
your website?

Enter your URL and get an instant security score. We check SSL, HTTP headers, vulnerabilities, exposed files and more — free.

https://
No account needed
Results in ~3 min
Non-intrusive
12
Security modules
3 min
Scan time
OWASP
Top 10 coverage
What you get

Free scan. Full report.
PDF delivered.

The free scan gives you your score and top findings. Upgrade to get the full PDF report with remediation steps, OWASP checklist and copy-paste fix configs.

📄
Professional PDF report
Every finding documented with severity, impact and exact remediation steps.
🗺
Remediation roadmap
Prioritised fix list — critical first. Copy-paste configs for Nginx and Vercel.
OWASP compliance checklist
Full Top 10 checklist you can share with clients or your security team.
📬
Delivered to your inbox
Report sent by email. Re-scan anytime and track your score over time.
Get full report →
From €9/mo  ·  Cancel anytime
Driftn mascot
/100
0
Critical
0
High
0
Medium
0
Low
Top findings
Detected technologies
SSL certificate
🔒
Unlock the full security report
Your scan is complete. Get the professional PDF report with all findings, step-by-step remediation and an OWASP compliance checklist.
Full vulnerability details
Professional PDF report
Remediation roadmap
Exposed API endpoints
Backup files detected
OWASP Top 10 checklist
€9
/month · Dev plan
Get full report + PDF →
Cancel anytime · Instant access · 7-day free trial
What we check
12 security modules, one scan
SSL / TLS
Certificate validity, expiry, protocol version and HSTS enforcement.
Security Headers
CSP, X-Frame-Options, HSTS, Referrer-Policy and Permissions-Policy.
OWASP Top 10
Injection points, XSS vectors, broken auth and misconfigurations.
DNS & Network
DNS records, open ports, subdomain exposure and network risks.
API Endpoints
Exposed REST, GraphQL and unauthenticated API access detection.
Exposed Files
Backup files, .env exposure, admin panels and sensitive paths.
WAF Detection
Identifies Web Application Firewalls and their bypass surface.
CMS & Stack
Technology fingerprinting: framework, server, CDN and versions.
JavaScript Analysis
Client-side secrets, hardcoded keys and insecure third-party scripts.