Direct answer
What this audit tells you
FreeScan checks browser-facing security evidence that can be requested safely without authentication or exploitation. It identifies public configuration problems worth investigating while clearly separating a website security check from a penetration test.
What you receive
One report, three practical outcomes
Transport and resources
Confirm HTTPS and identify insecure resources that can trigger warnings or weaken a secure page.
Browser protections
Review CSP or frame protection, HSTS, content-type controls, referrer policy, and permissions policy.
Public exposure
Probe a small allowlist and require recognizable file signatures so generic HTML fallbacks do not become critical failures.
Workflow
Use the evidence before changing the website
Step 1
Reproduce the response
Confirm the exact public header, form action, resource, or file signature before changing infrastructure.
Step 2
Apply the narrowest control
Prefer targeted server, CDN, header, or access-rule corrections over disabling security systems broadly.
Step 3
Retest legitimate workflows
Verify forms, payments, authentication, embeds, and required third-party resources after deployment.
Methodology
Review the checks behind this audit
Related audits
Follow the subject-specific path
Limits
What this public audit does not claim
- The scan does not authenticate, exploit vulnerabilities, enumerate infrastructure, or test private endpoints.
- A high score cannot prove that application code, dependencies, cloud permissions, or internal systems are secure.
- Critical findings should be reproduced and handled using an incident-safe process.
Check the current public page
Run the deterministic scan, inspect the evidence, and keep the existing page unchanged until a finding is reproduced.
Start a free audit