Skip to content

What it checks

Encryption

Whether visitors reach your site over a private, trusted connection.

How it is checked

Sentinel connects the way a browser does and reads the certificate your site presents. It tries each version of the encryption protocol to see which ones your server still accepts.

  • Certificate. The certificate your site presents: its dates, the names it covers and who issued it.
  • Encryption versions. Which versions of TLS your server accepts.
  • HTTPS everywhere. Whether the site answers over HTTPS and sends plain-HTTP visitors there.
  • Password forms. Whether any password form is on, or sends to, an unencrypted page.

What it can find

Your site's security certificate has expired

Fix now

Someone could take data or control of the site today.

What it is
The certificate that lets browsers trust your site ran out. Visitors now see a full-page warning that the site is not secure, and most will leave.
Why it matters
Customers cannot reach you without clicking through a warning, and anyone who does is no longer protected from someone listening in.
How to fix it
Renew the certificate with whoever issued it, or switch to a free automatically renewing one from Let's Encrypt, which most hosts offer in their control panel.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Your site's security certificate is about to expire

Fix soon

A real weakness that an attacker would look for.

What it is
The certificate that lets browsers trust your site runs out soon. If it is not renewed, visitors will see a full-page warning instead of your site.
Why it matters
An expired certificate takes the site offline for most visitors until someone fixes it.
How to fix it
Renew the certificate with whoever issued it. If renewal is meant to be automatic, it has stopped working: check the host's control panel for errors.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Your security certificate is for a different address

Fix soon

A real weakness that an attacker would look for.

What it is
The certificate your site presents does not list this address. Browsers show a warning because they cannot tell whether they reached the right site.
Why it matters
Visitors see a security warning, and the encryption cannot be trusted to be with you.
How to fix it
Issue a new certificate that lists every address the site is reached at.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Browsers do not trust your security certificate

Fix soon

A real weakness that an attacker would look for.

What it is
The certificate was not issued by an authority browsers recognise, or part of its chain is missing. Visitors see a security warning.
Why it matters
A certificate nobody can verify gives visitors a warning and no assurance they have reached you.
How to fix it
Install a certificate from a public certificate authority such as Let's Encrypt, including the intermediate certificates the authority provides.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Your server still accepts outdated encryption

Should fix

Makes an attack easier or more damaging.

What it is
Your server accepts connections using old versions of TLS that have known weaknesses and were retired by every major browser.
Why it matters
It lets an attacker who can interfere with a connection push it down to encryption that can be broken. It also fails card-payment security rules.
How to fix it
In the web server or hosting control panel, set the minimum TLS version to 1.2.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Your site does not offer an encrypted connection

Fix soon

A real weakness that an attacker would look for.

What it is
The site only answers over plain HTTP. Everything sent between a visitor and the site, including anything they type, can be read or changed on the way.
Why it matters
Browsers mark the site Not Secure, search engines rank it lower, and anything a customer submits can be intercepted.
How to fix it
Turn on HTTPS in the hosting control panel. Most hosts offer a free certificate.On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

Visitors can still use your site without encryption

Should fix

Makes an attack easier or more damaging.

What it is
The site works over HTTPS, but the plain HTTP address shows the site instead of sending visitors to the encrypted one.
Why it matters
Anyone who types the address without https, or follows an old link, uses the site unprotected without knowing.
How to fix it
Add a redirect from HTTP to HTTPS in the web server settings or the hosting control panel. Many hosts have a switch called Force HTTPS.WordPress: set both site addresses to https in Settings, General, and switch on Force HTTPS at the host. On a hosted builder such as Squarespace, Wix or Shopify this is managed for you; if it shows up there, contact their support.

A password form sends passwords without encryption

Fix soon

A real weakness that an attacker would look for.

What it is
A page with a password box is served over plain HTTP, or sends what is typed to a plain HTTP address.
Why it matters
Passwords typed there can be read by anyone on the same network, such as public wifi.
How to fix it
Serve the login page over HTTPS and make the form's target address an https one.

See which of these your own website has.

Start free trial