Scan your site

Enter a site you own. We'll inspect it from the outside — the way an attacker sees it — and hand you a graded report with plain-English fixes.

We'll check it over HTTPS. You don't need to type https://.

What does this scan actually do? (Read me — it matters)

This is a non-intrusive scan. It only does what a normal web browser already does: it loads your public pages, reads the response headers, checks your public DNS records, inspects your TLS certificate, and requests a handful of well-known filenames (like .env or .git/config) to see if they're accidentally downloadable.

It does not "hack" anything. It never injects attack payloads, never brute-forces logins, never tries to break in, and never changes anything on your site. That kind of active penetration testing is illegal without a signed agreement — and it could get you in trouble if pointed at a site you don't own. IndieShield finds the weaknesses a real attacker would exploit, without exploiting them.

Everything runs on our server (the "back end"), not in your browser, so results reflect what the wider internet actually sees.