Is your site hardened against attacks?
TLS certificate + protocol version, HSTS, Content-Security-Policy, X-Frame-Options + clickjacking, MIME nosniff, CMS / framework version, admin path fingerprint, WAF/CDN layer — measure your attack surface in 8 signals.
- Result in 45 seconds
- No signup required
- Reports in Turkish + English
Four pillars of SecO web-side
We audit the website-side of security optimization across four focus areas.
Protocol & Encryption
TLS 1.3 certificate, HSTS strict-transport-security + max-age + preload, WAF/CDN layer (Cloudflare, Sucuri, Akamai).
Security Headers
Content-Security-Policy default-src baseline, X-Frame-Options DENY or CSP frame-ancestors, X-Content-Type-Options: nosniff.
Software Hygiene
CMS / framework version detection — hide generator/X-Powered-By, urgent renewal of EOL versions.
Access Surface
Standard admin paths (/wp-admin, /admin, /administrator) should not return 200 directly to bot probes.
See your security score now
Drop a URL — your SecO audit and action list are ready in 45 seconds.