Skip to content
8 checks·Security web-side

Is your site hardened against attacks?

TLS certificate + protocol version, HSTS, Content-Security-Policy, X-Frame-Options + clickjacking, MIME nosniff, CMS / framework version, admin path fingerprint, WAF/CDN layer — measure your attack surface in 8 signals.

Which check do you want?
  • Result in 45 seconds
  • No signup required
  • Reports in Turkish + English

Four pillars of SecO web-side

We audit the website-side of security optimization across four focus areas.

Protocol & Encryption

TLS 1.3 certificate, HSTS strict-transport-security + max-age + preload, WAF/CDN layer (Cloudflare, Sucuri, Akamai).

Security Headers

Content-Security-Policy default-src baseline, X-Frame-Options DENY or CSP frame-ancestors, X-Content-Type-Options: nosniff.

Software Hygiene

CMS / framework version detection — hide generator/X-Powered-By, urgent renewal of EOL versions.

Access Surface

Standard admin paths (/wp-admin, /admin, /administrator) should not return 200 directly to bot probes.

See your security score now

Drop a URL — your SecO audit and action list are ready in 45 seconds.

Which check do you want?
SecO Check — AIDE | AIDE