Client Login

Is your website properly locked up? Twelve things a hacker checks first, checked for you in two minutes.

The security report checks the twelve things anyone can see about your website from outside: whether every page is encrypted and stays that way, whether your server switches on the protections browsers offer, whether configuration files and backups are sitting where anyone can read them, whether the software your site runs on announces an out-of-date version, and whether your forms send what people type in the clear. Each one comes with the fix written in plain language.

It starts with the free scan. Put in your web address and your email, and your security results come with your score, with the full report one click away if you want it.

Check my website

No card. No account. The scan and the score are free.

What the report tells you

yourbusiness.com

5 checks need attention. 7 already pass.

  • Needs attention: A backup of the site's configuration is readable by anyone/wp-config.php.bak answers, with the database password inside
    Exposed files
  • Needs attention: The site runs software with known holesjQuery 1.12.4 on every page. Versions below 3.5 have known cross-site scripting holes
    Software versions
  • Needs attention: The unencrypted address does not send visitors to the secure onehttp://yourbusiness.com answers with the site instead of redirecting
    HTTP redirect
  • Passes: Every page is served over HTTPS
  • Passes: Forms send what people type encrypted
What to do about the backup file

Delete the file from the web folder, or move it outside the site. Then change the database password and every other secret it holds: assume it has been read.

Every check that needs attention comes with its fix, and the report lists all twelve.

Twelve checks. Four for encryption, four for the server, four for what is exposed.

Each one is something a scanner can see from outside, and each one is named in the report with where it was found.

Encryption

Whether everything between the visitor and your site travels encrypted.

  • Every page is served over HTTPS
  • The unencrypted address sends visitors straight to the secure one
  • The browser is told to always use HTTPS from then on
  • Nothing on the page loads over a plain http:// address

Server settings

The protections a server switches on with one line of configuration.

  • Other sites cannot show your pages inside their own
  • The browser cannot be tricked about what kind of file it is loading
  • The server does not announce its software and version
  • Cookies are marked so they only travel encrypted

What is exposed

What the server answers that it never should.

  • Configuration files and backups are not readable by anyone
  • Folders do not list every file inside them
  • No library with known holes, and no page announces its platform version
  • Forms send what people type encrypted

What is free, and what is in the security report.

The scan is the same two-minute scan behind every Obris Audit report, so you only ever run it once.

FreeNo card, no account

The scan and the score

Where your website stands, in two minutes.

  • Your website score out of 100, with all seven categories
  • How many of the twelve security checks pass
  • How many need attention, in each of the three areas
  • The three things worth doing first on the whole site
Check my website
$49Once. Any three reports for $99. Not a subscription.

The security report

Every check that needs attention, and what to do about it.

  • Each failed check named, with the header or setting it is about
  • Where it fails: which pages, which paths, which forms
  • The fix in plain language, ready to hand to whoever looks after your site
  • What it means, so you can tell how much it matters
  • The checks that already pass, so you know what to leave alone
  • Yours to keep: a link that keeps working, and a PDF

The $49 comes off any Obris Launch project you start within 60 days.

Start my security report

What a scanner can see, and what needs a person.

It is a careful check of the things anyone can see about your site from outside: the encryption and the headers that enforce it, the protections the server switches on, what answers at a handful of well-known addresses, and the software the pages announce. Those are the things most small business websites get wrong, and most of them are one line of configuration to put right, with the report beside whoever looks after your site.

It is not a penetration test. It cannot see your backups, your logins, your plugins, or anything inside your hosting account, and it does not try. Those need a person with access, and if the report finds a reason to bring one in, it says so. For everyone else, this is the honest first step, and it is the one the specialists start with too.

Questions about the security report, answered straight.

No. One scan reads your site once and every report comes from it. Run the free scan, and your security results come with your score, with the report one click away. If you later want the full website report, the SEO report or the compliance report, they are in the same email, from the same scan.

No. It reads your public pages the way a browser does, asks for a handful of well-known addresses the way a browser would, and measures what comes back. It does not log in, it does not try passwords, and it does not change anything.

The scan and the score are free. The security report is $49, once. Any three reports, on one website or three, are $99. Nothing renews.

Yes. There is a button on the report that sends it to us for a quote, the whole list or only the fixes worth doing first. The $49 comes off the work.

See where your website stands before you decide anything.

Put in your web address. The scan runs, the score comes back, and your security results are marked on it.

Check my website