Free grade in a couple of minutes · no login, no attack traffic

See what an attacker already sees on your site. Graded.

Paste your domain. See what your site already exposes to anyone on the internet, graded, in a couple of minutes. Free to run.

External, read-only scan. We only request public URLs - never log in, never send attack traffic.

The reality

30% of sites we scan have a serious problem open right now.

A known-vulnerable library in your bundle. A Grafana dashboard or a Jenkins console answering the public internet. Either one still grades a C, which is why only 70% of the sites we check earn an A or B. A letter tells you that something is wrong. It never tells you which file.

A · 9%B · 61%C · 16%D · 3%E · 6%F · 5%
Distribution across 280 graded sites. This is a self-selected sample of sites submitted to SurfaceCheckr, not a survey of the web.
The outside view

Your site tells strangers more than you think.

Before anyone logs in, your servers hand out headers, certificates, DNS records and files to whoever asks. Most of it is harmless. Some of it is a map. We read all of it - the way an attacker would - and tell you what stands out.

$ yoursite.com
what the street sees
Servernginx/1.18.0
FrameworkX-Powered-By: Express
DNS / emailSPF missing, DMARC p=none
TLS certexpires in 9 days
Exposed/.git/config is readable
Every fact here was read from outside. No login, no payload, no touching the backend.
The verdict

One real leak is a hard fail.

Findings are weighted by how much they actually expose, then rolled into a single A-to-F grade a non-engineer can act on. But an exposed key, a public bucket or an expired certificate pins the report to an F on its own, however clean everything around it looks.

A
B
C
D
E
F
why this site landed on F
  • ·/.env downloadable by anyone
  • ·no HTTPS redirect, no HSTS
  • ·SPF and DMARC missing
A grade is the first thing a stranger forms about you, and they form it in seconds.
What you get

The grade tells you something is wrong. The report tells you which line to change.

Free, you see how bad it is. Unlocked, you see the file, the key, the exact path an attacker requested, and the change that closes it. Here is the same finding, both ways.

What everyone seesFree
critical
high

You learn that something serious is open, and how bad it is. You do not learn which file, which key, or where to look. Neither does anyone else you send the link to.

  • No file name
  • No path
  • No fix
What you see when you unlockThe same finding
criticalExposed: /.env file readable over HTTP SC-02001

Your deployment serves /.env to anyone who asks. It holds a live database connection string and a payment-processor secret key. No login, no exploit, one GET request.

Found on: https://shop.acme-demo.example/.env

Fix: Block dotfiles at the web server so /.env can never be served, then rotate every credential it contained.

Where: Nginx, Apache, or your host's redirects file.

Every finding, named, with the exact path and the change that closes it. This one is real, from the example report.

  • The file, named
  • The exact path
  • The fix, with the config to paste
Scan my site free

Your grade is free. $15/month unlocks every finding and its fix, then keeps watching: the moment a bad deploy exposes something new, you get an email - not a monthly report you have to read. Or from $19 once if you just need this one report.

Cancel anytime. If the report isn't worth it, ask for a refund within 14 days.

How it works

Three steps. No agent, no access, no attack traffic.

  1. 1

    Paste a domain

    Any site you can reach. No account, no install, no permission needed to see what's already public.

  2. 2

    We read the surface

    Headers, TLS, exposed files, admin panels, leaked secrets, DNS and email hygiene - all read passively, in parallel.

  3. 3

    Get a graded report

    A shareable report at its own private URL: your grade, how many issues we found, and - once unlocked - every fix.

Every scan runs 500+ checks, every time.

Plus 2,000+ daily-synced WordPress plugin rules and a live database of 220,000+ library CVE signatures.

Learn

Not sure what a finding means? We explain every one.

Plain-English guides to what an attacker can see on your site, and the one-line fix for each. No jargon for its own sake.

Built it with AI?

Lovable, Bolt, Cursor, Supabase: see what your app left exposed.

The AI shipped the feature. It never checked what it exposed: a key in the browser, a table anyone can read, the reachable .env. Here is the short list, and how to see it from outside.

See what it leaks

Find out what your site is leaking.

Paste your domain. The grade is free, and you'll have it in a couple of minutes.

External, read-only scan. We only request public URLs - never log in, never send attack traffic.

Cancel anytime. If the report isn't worth it, ask for a refund within 14 days.

Or read a real report first →