What it checks
Encryption
Whether visitors reach your site over a private, trusted connection.
How it is checked
Sentinel connects the way a browser does and reads the certificate your site presents. It tries each version of the encryption protocol to see which ones your server still accepts.
- Certificate. The certificate your site presents: its dates, the names it covers and who issued it.
- Encryption versions. Which versions of TLS your server accepts.
- HTTPS everywhere. Whether the site answers over HTTPS and sends plain-HTTP visitors there.
- Password forms. Whether any password form is on, or sends to, an unencrypted page.
What it can find
Your site's security certificate has expired
Fix nowSomeone could take data or control of the site today.
- What it is
- The certificate that lets browsers trust your site ran out. Visitors now see a full-page warning that the site is not secure, and most will leave.
- Why it matters
- Customers cannot reach you without clicking through a warning, and anyone who does is no longer protected from someone listening in.
- How to fix it
- Renew the certificate with whoever issued it, or switch to a free automatically renewing one from Let's Encrypt, which most hosts offer in their control panel.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Your site's security certificate is about to expire
Fix soonA real weakness that an attacker would look for.
- What it is
- The certificate that lets browsers trust your site runs out soon. If it is not renewed, visitors will see a full-page warning instead of your site.
- Why it matters
- An expired certificate takes the site offline for most visitors until someone fixes it.
- How to fix it
- Renew the certificate with whoever issued it. If renewal is meant to be automatic, it has stopped working: check the host's control panel for errors.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Your security certificate is for a different address
Fix soonA real weakness that an attacker would look for.
- What it is
- The certificate your site presents does not list this address. Browsers show a warning because they cannot tell whether they reached the right site.
- Why it matters
- Visitors see a security warning, and the encryption cannot be trusted to be with you.
- How to fix it
- Issue a new certificate that lists every address the site is reached at.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Browsers do not trust your security certificate
Fix soonA real weakness that an attacker would look for.
- What it is
- The certificate was not issued by an authority browsers recognise, or part of its chain is missing. Visitors see a security warning.
- Why it matters
- A certificate nobody can verify gives visitors a warning and no assurance they have reached you.
- How to fix it
- Install a certificate from a public certificate authority such as Let's Encrypt, including the intermediate certificates the authority provides.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Your server still accepts outdated encryption
Should fixMakes an attack easier or more damaging.
- What it is
- Your server accepts connections using old versions of TLS that have known weaknesses and were retired by every major browser.
- Why it matters
- It lets an attacker who can interfere with a connection push it down to encryption that can be broken. It also fails card-payment security rules.
- How to fix it
- In the web server or hosting control panel, set the minimum TLS version to 1.2.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Your site does not offer an encrypted connection
Fix soonA real weakness that an attacker would look for.
- What it is
- The site only answers over plain HTTP. Everything sent between a visitor and the site, including anything they type, can be read or changed on the way.
- Why it matters
- Browsers mark the site Not Secure, search engines rank it lower, and anything a customer submits can be intercepted.
- How to fix it
- Turn on HTTPS in the hosting control panel. Most hosts offer a free certificate.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
Visitors can still use your site without encryption
Should fixMakes an attack easier or more damaging.
- What it is
- The site works over HTTPS, but the plain HTTP address shows the site instead of sending visitors to the encrypted one.
- Why it matters
- Anyone who types the address without https, or follows an old link, uses the site unprotected without knowing.
- How to fix it
- Add a redirect from HTTP to HTTPS in the web server settings or the hosting control panel. Many hosts have a switch called Force HTTPS.WordPress: set both site addresses to https in Settings, General, and switch on Force HTTPS at the host. On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.
A password form sends passwords without encryption
Fix soonA real weakness that an attacker would look for.
- What it is
- A page with a password box is served over plain HTTP, or sends what is typed to a plain HTTP address.
- Why it matters
- Passwords typed there can be read by anyone on the same network, such as public wifi.
- How to fix it
- Serve the login page over HTTPS and make the form's target address an https one.