Skip to main content
UNPWNED
Free website security check

IS YOUR WEBSITE SECURE?

Check publicly observable configuration risks. Run a bounded public scan free. No signup required.

149 security checksTrusted by 900+ developersNo credit card

Recently scanned domains show instantly. New domains run a fresh scan. Some websites may block external scanners, which can affect results. See exactly which 149 checks run free and which checks reach the expanded 702 configured-check set only after current ownership proof.

149 SECURITY CHECKS
DETERMINISTIC ANALYSIS
TRUSTED BY 900+ DEVELOPERS

Domain owner? Request Public Lookup removal via Opt Out or [email protected]

DISCLAIMER: This security score is generated by deterministic automated scanning and scoring. It is provided for informational purposes only and does not constitute a security audit, penetration test, certification, or professional security assessment. Results reflect a point-in-time snapshot. The absence of findings does not mean a domain is free of vulnerabilities. UNPWNED makes no warranty of completeness or accuracy.

What the public check covers

149 checks run without an account. They are the ones that read what your site already tells the internet, so running them on a domain costs its owner nothing more than an ordinary visit.

Dependencies & CVEs

76

The known-vulnerable software you are running. Only version-linked matches backed by an observed fingerprint are reported.

76 of 94 checks

DNS & Email Security

43

Whether someone can send mail as you, and what your DNS reveals about the hosts you did not mean to publish.

43 of 139 checks

Browser Security Controls

21

The instructions your server gives the browser. When these are missing the browser has no reason to refuse an attacker.

21 of 59 checks

Compliance Signals

8

Reported for completeness and never scored. A missing privacy policy is a legal problem, not an attack surface, so it does not affect your grade.

8 of 64 checks · reported, never scored

SSL/TLS Configuration

1

Whether the encrypted connection is actually trustworthy, and what your certificate history reveals about the rest of your estate.

1 of 8 checks

And what stays closed

553 of the 702 currently enabled checks do not run on a domain typed in by a stranger, and these 4 categories stay shut entirely. This is not a paywall. These checks send traffic that an ordinary visitor would not send, and we are not willing to send it at somebody's infrastructure on an unproven claim of ownership. Proving current control of the host opens them.

Secrets & Credentials

52

Anything that hands an attacker a working key. These are the findings that turn a curious visitor into an authenticated one.

Authentication & APIs

136

The endpoints behind your app. This is the largest group, because it is where an outside-in scan can most directly demonstrate real access.

Database & Storage Exposure

143

Whether your data is readable without an account. These are the findings that most often turn out to be a real breach rather than a hardening gap.

Content Integrity

7

Whether your site shows search engines something different from what it shows visitors. This is how an SEO compromise stays invisible to the owner.

Common questions

What does this free website security check actually test?

It runs 149 checks against signals any browser or mail server could already observe about a public domain: response headers and browser security controls, DNS and email authentication records, the TLS certificate, publicly disclosed vulnerabilities in software versions the site announces about itself, and a handful of compliance signals. No account is needed and nothing is sent to your site that an ordinary visitor could not send.

Why do some checks only run after I prove I own the domain?

Because the remaining checks are not a paywalled tier, they are a different kind of request. Probing authentication endpoints, guessing storage buckets, reading sensitive paths and testing database exposure means sending traffic at somebody else's infrastructure on the word of a stranger who typed a domain into a box. UNPWNED will not do that. Proving current control of the host raises the ceiling from 149 checks to 428, and a deep scan on a verified domain reaches 702.

Can a scan tell me whether my website is secure?

No scan can, and any tool that says otherwise is selling certainty it does not have. What this one establishes is narrower and more useful: what your site currently exposes to anyone on the internet, which of those exposures are known to be exploited, and what changes when you fix them. Findings prove a problem exists. An absence of findings proves only that these particular checks came back clean.

How long does a scan take?

About a couple of minutes for a public scan. If the domain has been scanned recently you see the stored result immediately; a domain we have not seen runs fresh. Deep scans on verified domains run many more checks and take longer.

Do I need to sign up or enter a credit card?

No. The public check runs without an account and without payment details. An account raises the per-month scan allowance and reveals every finding title we detected rather than a sample, and paid plans add the fix instructions, the exact affected component, monitoring and history.

Can I check a website I do not own?

Yes, within the bounded public profile, which is deliberately limited to what an ordinary visitor could observe. It is the same reason the intrusive checks stay closed. If you own a domain that appears in the public lookup and you want it removed, use the opt-out form and it is taken down.

What happens if my firewall blocks the scanner?

The report says so instead of quietly reporting a clean result. A check that was refused is recorded as refused, never as passed, and a scan with too little completed coverage does not receive an official grade at all. If a CDN or WAF is turning the scanner away, allowing it through gives you a real result rather than an optimistic one.

How is this different from an SSL checker or a headers grader?

Single-purpose tools answer one question well and leave you to assemble the picture. This scan runs the certificate check, the header check, the DNS and email authentication checks and the known-vulnerability lookup in one pass, then scores them together so you can see which finding actually matters first. The individual tools are here too if one question is all you need.

One question at a time

If you already know which answer you need, these run the single check on its own.