Passive security audit

A safe, passive look at your website's security posture

AuditScout checks the public, observable parts of your site — HTTPS, security headers, and common misconfigurations — and explains what to harden. No exploits, ever.

No login required for your first audit.

Who it's for

Owners, founders, and builders who want a quick, honest read on their site's public security hygiene — and a clear list of low-risk headers and settings to improve.

Sound familiar?

Security feels opaque

You don't know whether your site has the basics in place, and proper audits feel expensive and far off.

Header config is easy to miss

CSP, HSTS, and frame protections are simple to add but quietly absent on most sites.

Trust depends on it

Visitors and customers increasingly notice when a site looks insecure or out of date.

You don't want anything risky

You need a check that can't break or alter your live site.

How AuditScout helps

Public, observable checks only

HTTPS enforcement, security headers, exposed version info, and common public-file misconfigurations.

Plain-English hardening steps

Each finding explains the gap and the low-risk fix — like adding a starter CSP or frame protections.

Honest about its limits

This is hygiene, not a penetration test. AuditScout tells you clearly where a professional review is warranted.

Example findings

The kind of prioritized, plain-English items a real audit surfaces.

  • No Content-Security-Policy

    Adding a baseline CSP reduces exposure to script injection and is a quick, safe win.

  • Missing frame protections

    No X-Frame-Options or frame-ancestors directive leaves the site open to clickjacking.

  • Server version exposed

    Response headers reveal software versions that needlessly aid automated scanners.

Example Claude / Cursor prompt

Every audit ends with a ready-made prompt like this — paste it into Claude or Cursor to start shipping the fixes.

Copy/paste upgrade prompt

Harden the public security headers on MY_URL based on the passive audit below. These are configuration changes only — do not attempt any intrusive testing. Explain each change.

Work through these findings, highest impact first:
1. [HIGH] Add a baseline Content-Security-Policy header, then tighten it over time.
2. [HIGH] Set X-Frame-Options: DENY (or a frame-ancestors CSP directive) to prevent clickjacking.
3. [MED] Suppress detailed Server / X-Powered-By version headers.
4. [LOW] Confirm HSTS is set with a reasonable max-age.

Show me the exact header/config changes for my stack.

Frequently asked questions

Is this a penetration test?
No. AuditScout performs passive public checks only. It does not replace a professional penetration test, security audit, legal review, or compliance assessment. No exploits, login attempts, brute force, or intrusive testing are performed.
Can the scan harm my site?
No. It only reads public information your own visitors already receive — it never logs in, sends payloads, or alters anything.
What does it actually check?
Public, observable security hygiene: HTTPS, common security headers, exposed version info, and common public-file misconfigurations.
When should I hire a professional?
For anything handling sensitive data or compliance requirements, treat AuditScout as a first pass and engage a qualified security professional for a full assessment.

Audit your site now

One URL. A prioritized beta report with plain-English fixes. No login required.

Passive & safe — public checks only.