Security Check
Security headers checked
across your whole site.
Paste a URL. We run a full Rocket Vitals scan and surface CSP, HSTS, cookie, and SSL issues first.
Free to start. Full site scan in about 90 seconds — security findings are prioritized in the report.
SSL monitoring
Expiry & validity
Header coverage
30+ security headers
Cookie audit
Secure, HttpOnly, SameSite
Mixed content
HTTP on HTTPS pages
What we check
Headers, cookies, and TLS — what to fix first.
We check the signals browsers and attackers actually care about.
SSL certificate status
Checks whether your certificate is valid, expired, or expiring soon.
HTTPS enforcement
Verifies HTTP→HTTPS redirects and flags mixed content on HTTPS pages.
Content-Security-Policy
Detects missing CSP and dangerous directives: unsafe-inline, unsafe-eval, wildcards.
HSTS header
Flags sites missing Strict-Transport-Security — browsers can be downgraded on first visit.
Clickjacking protection
Checks X-Frame-Options and CSP frame-ancestors.
Cookie security flags
Inspects cookies for missing Secure, HttpOnly, and SameSite attributes.
Subresource Integrity
Flags external scripts loaded without integrity hashes.
Additional security headers
Checks X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and COOP/COEP/CORP.
Rocket Vitals by Rocket Park
Scan for security gaps.
You get a prioritized list with the missing headers and why they matter — not a checklist dump.
Scan for security issues →