Open the page in a browser
We load the URL, follow redirects and record server responses, cookies and page resources.
Check HTTPS, security headers, CSP, cookies and external page resources. Get a score, collected evidence and recommendations for improving your configuration.
We load the URL, follow redirects and record server responses, cookies and page resources.
We analyse transport, headers, CSP policies, cookie attributes, SRI and CORS using the page load data.
Overall and category scores, check results, collected evidence and prioritised recommendations. Download the report as JSON.
HTTPS, HSTS, and mixed content protection
Security response headers
Content Security Policy configuration
Cookie security attributes
Subresource Integrity and CORS
Overall and category scores, check results, collected evidence and prioritised recommendations. Download the report as JSON.
Milten’s security audit checks the settings a browser receives when loading a page. It brings server response headers, cookie details and external resources into one report. Run it after configuring a web server, connecting a CDN or releasing a new site version to see which settings need attention without inspecting every response manually in DevTools.
The scanner checks HTTPS, HSTS and mixed content, along with X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers. A separate category covers Content Security Policy, showing detected directives and findings about unsafe-inline and unsafe-eval. Headers come from the main page response after redirects, so the result describes the URL actually loaded.
The cookie check shows whether Secure, HttpOnly and SameSite attributes are present. The report includes cookie names, domains and attributes without their values. For external resources, the service analyses Subresource Integrity and observed CORS settings. These details help distinguish your site’s settings from those of connected third-party resources.
Start with high-priority recommendations, then open the relevant category and review the collected evidence. The overall score helps compare runs, but specific findings and application context matter more. After making changes, audit the same page again and download the report as JSON. Results describe one page load and do not establish the security of business logic or authentication flows.
A passive check of the loaded page configuration. Findings require context and do not replace a penetration test.
Adjacent checks help reveal nearby causes across speed, code, accessibility, SEO, and page state after user scenarios.
Check page structure, validity, semantics, and required meta tags.
OpenWCAG audit: contrast, alt text, landmarks, aria attributes, and keyboard navigation. Includes fixes and examples.
OpenJavaScript performance, code coverage during load, bundle composition, and third-party scripts.
OpenStylesheet size, unused selectors, duplicates, and specificity explosion. See what can be removed safely.
OpenEnter a URL to see check results and understand which settings need attention.
Run security auditWe use cookies to give you a better experience on our site. You can learn more about how we use cookies in our privacy policy.