HTTPS & Redirects
Checks HTTPS availability and whether the equivalent HTTP URL redirects to HTTPS.
Inspect public website HTTPS and security posture without intrusive scanning.
A non-invasive analyzer for TLS certificates, browser security headers, cookies, mixed content, CORS, and security.txt.
/api/website-security-analyzer-api/v1/analyze-website
What it does
Website Security Analyzer reviews only publicly accessible responses from a supplied public HTTP or HTTPS URL. It follows a small, validated redirect chain, checks HTTPS availability and HTTP-to-HTTPS behavior, inspects certificate metadata, evaluates security headers and cookie attributes, identifies insecure resources in returned HTML, summarizes CORS and software-disclosure headers, checks /.well-known/security.txt, and produces an explainable score with severity-grouped recommendations. It never exploits vulnerabilities, authenticates to the target, brute-forces paths, or scans private networks.
Checks HTTPS availability and whether the equivalent HTTP URL redirects to HTTPS.
Reports trust, hostname matching, issuer, subject, expiration, remaining days, and negotiated TLS version.
Evaluates security-related response headers and cookie Secure, HttpOnly, and SameSite attributes.
Detects mixed-content references and insecure HTTP resources without requesting those resources.
Summarizes software-disclosure headers and potentially permissive cross-origin policy signals.
Groups findings by severity and attaches a practical recommendation to every detected issue.
Stable endpoints
/api/website-security-analyzer-api/v1/analyze-websitePerform a bounded, non-invasive security and HTTPS configuration analysis of one public website URL.
Simple monthly plans
Plus includes 10× the Free quota. Pro includes 500× the Free quota.
Free access for testing and light usage.
10× the Free request quota.
500× the Free request quota for production workloads.