Free & instant — no email, no signup

Website Security Score

One of the free tools from KinetixSEO, an SEO and AI-citation (GEO) checker. One bundled score combining HTTP security headers, cookie flag hygiene, mixed content, and TLS certificate health — the same fundamentals a trust-score scanner like Nyrolo or Mozilla Observatory checks, in one pass, with a fix for every finding.

Frequently asked questions

How is the security score calculated?

It combines two halves, weighted evenly: your HTTP security headers (HSTS, CSP, X-Frame-Options, and the rest, plus cookie flag hygiene, mixed content, and insecure form actions) and your TLS certificate health (validity, chain and hostname trust, protocol version, key strength). A site with no HTTPS at all scores 0 on the TLS half — there is no "not applicable" free pass for missing encryption.

Why isn’t there a reputation / malware-blocklist check like some other scanners have?

Checking a URL against Google’s threat lists uses a metered API. To keep this free tool genuinely free and instant for anyone, that check runs as part of a full KinetixSEO site analysis instead, where it’s scoped to sites you’re actually tracking rather than every anonymous visitor to this page.

How is this different from Mozilla Observatory, securityheaders.com, or a scanner like Nyrolo?

Same fundamentals — headers and TLS are checked the same way everywhere. The difference is what happens next: KinetixSEO’s full site analysis ties every one of these findings to a fix (a copy-paste header, an nginx/Apache config line) and tracks whether it stays fixed on your next scan, instead of leaving you with a score and a checklist.

Does a low security score hurt my search rankings?

Not directly as a ranking factor for most of these checks, but indirectly it matters a lot: Chrome shows hard warnings for expired or untrusted certificates, which tanks click-through and conversion instantly, and a site that looks unmaintained or insecure is one both visitors and links pass over.

Are cookie flags (Secure, HttpOnly, SameSite) really a security issue?

Yes. Secure stops a cookie being sent over a plain-HTTP connection, HttpOnly blocks it from being read by injected JavaScript (mitigating XSS-driven session theft), and SameSite limits it being attached to cross-site requests (mitigating CSRF). Missing all three on a session cookie is one of the more common findings this tool surfaces.

This is one check from KinetixSEO's full SEO/GEO audit. Want the complete picture — Core Web Vitals, AI-citation readiness, technical SEO health, and tailored fixes? Run the free full checker.