Skip to content

What it checks

13 checks in 7 areas, able to report 44 different problems. This list is made from the code that runs, so what you read here is what happens.

Encryption

Whether visitors reach your site over a private, trusted connection.

Certificate

The certificate your site presents: its dates, the names it covers and who issued it.

  • Your site's security certificate has expiredFix now
  • Your site's security certificate is about to expireFix soon
  • Your security certificate is for a different addressFix soon
  • Browsers do not trust your security certificateFix soon

Encryption versions

Which versions of TLS your server accepts.

  • Your server still accepts outdated encryptionShould fix

HTTPS everywhere

Whether the site answers over HTTPS and sends plain-HTTP visitors there.

  • Your site does not offer an encrypted connectionFix soon
  • Visitors can still use your site without encryptionShould fix

Password forms

Whether any password form is on, or sends to, an unencrypted page.

  • A password form sends passwords without encryptionFix soon

How encryption is checked, and how to fix each problem

Browser protections

The instructions your site gives a visitor's browser to keep them safe.

Security headers

The protective headers sent with your home page.

  • Browsers are not told to always use encryptionWorth tidying
  • No limit on which scripts your pages may runWorth tidying
  • Other sites can display yours inside their own pagesWorth tidying
  • Browsers may guess at file typesWorth tidying
  • Full page addresses are shared with sites you link toWorth tidying

Cookies

The flags on each cookie your site sets.

  • A cookie can be sent without encryptionShould fix
  • A sign-in cookie can be read by scriptsShould fix

Mixed content

Scripts, frames and images loaded over plain HTTP from encrypted pages.

  • An encrypted page loads a script or frame without encryptionShould fix
  • An encrypted page loads images without encryptionWorth tidying

How browser protections is checked, and how to fix each problem

Exposed files

Files that were never meant to be public but can be downloaded by anyone.

Left-behind files

A fixed list of file names: version-control folders, settings files, backups, database dumps and keys.

  • Your site's source code can be downloaded by anyoneFix now
  • A file of passwords and keys can be read by anyoneFix now
  • A backup copy of your site's settings can be read by anyoneFix now
  • A copy of your database can be downloaded by anyoneFix now
  • A backup archive of your site can be downloaded by anyoneFix soon
  • A private key can be downloaded from your siteFix now
  • A file of user names and scrambled passwords can be read by anyoneFix soon
  • A hidden file lists the contents of a folder on your siteWorth tidying

Folder listings

Whether folders on the site show a list of their files.

  • A folder on your site shows a list of everything in itShould fix

How exposed files is checked, and how to fix each problem

Out-of-date software

Software your site says it runs that its maker no longer supports or has since updated.

Software versions

The WordPress and PHP versions your site states, against each maker's current releases, and any other version numbers it gives away.

  • Your site runs software its maker no longer supportsFix soon
  • Your site's software is behind the current releaseShould fix
  • Your server tells visitors exactly what software it runsWorth tidying

How out-of-date software is checked, and how to fix each problem

Exposed doors

Admin, setup and debugging pages that anyone on the internet can open.

Admin, setup and debug pages

A fixed list of addresses where installers, database tools, status pages and login pages usually live.

  • A setup page is open to anyoneFix soon
  • A diagnostics page shows your server's full configurationFix soon
  • Your database's control panel is open to the internetShould fix
  • A live status page for your server is publicShould fix
  • A developer's debugging tool is switched on for everyoneFix soon
  • Your admin sign-in page is open to the internetWorth tidying

How exposed doors is checked, and how to fix each problem

Email spoofing

Whether someone else can send email that appears to come from your domain.

Email sender records

The SPF, DKIM and DMARC records on your domain.

  • Anyone can send email that claims to be from your domainShould fix
  • Your list of allowed email senders does not block anyoneWorth tidying
  • Mail providers are not told what to do with forged email from your domainShould fix
  • Forged email from your domain is watched but not blockedWorth tidying
  • No email signing key was found for your domainWorth tidying

How email spoofing is checked, and how to fix each problem

Leaks in the page

Keys, internal addresses and error details visible in your pages to anyone who looks.

Keys and errors in pages

Every page and script already read, searched for keys, private addresses and error traces.

  • A secret key is visible in your site's pagesFix now
  • A service key is visible in your site's pagesWorth tidying
  • A page reveals an address inside your private networkWorth tidying
  • A page shows the details of an internal errorShould fix

How leaks in the page is checked, and how to fix each problem

What it does not check

  • Anything behind a login.
  • Whether forms, searches or logins can be attacked. Sentinel never submits a form or sends attack data.
  • Plugins, themes and other software whose version the site does not state.
  • Pages that only appear after a browser runs the site's scripts.
  • Other servers on your domain, such as mail servers or forgotten subdomains.