Skip to content
Milten
ServicesBlogAboutContact
EnglishРусскийالعربية中文日本語한국어EspañolDeutschItalianoFrançaisPortuguês
Sign in
ServicesBlogAboutContact
EnglishРусскийالعربية中文日本語한국어EspañolDeutschItalianoFrançaisPortuguês
HTTPS
  1. Home
  2. /Services
  3. /Security Audit

Security Audit

Check HTTPS, security headers, CSP, cookies and external page resources. Get a score, collected evidence and recommendations for improving your configuration.

How it works

From URL to recommendations

01 · URL

Open the page in a browser

We load the URL, follow redirects and record server responses, cookies and page resources.

02 · HTTPS / CSP

Check security settings

We analyse transport, headers, CSP policies, cookie attributes, SRI and CORS using the page load data.

03 · 0–100

Get a clear report

Overall and category scores, check results, collected evidence and prioritised recommendations. Download the report as JSON.

What we check

Five categories and a fix plan

HTTPS

Transport

HTTPS, HSTS, and mixed content protection

HTTPSHSTS
HEADERS

Headers

Security response headers

X-Frame-OptionsReferrer-Policy
CSP

CSP

Content Security Policy configuration

script-srcunsafe-inlineunsafe-eval
COOKIES

Cookies

Cookie security attributes

SecureHttpOnlySameSite
SRI / CORS

Subresources

Subresource Integrity and CORS

integrityAccess-Control-Allow-Origin
0–100

Recommendations

Overall and category scores, check results, collected evidence and prioritised recommendations. Download the report as JSON.

Observed dataJSON

Website security check online

Milten’s security audit checks the settings a browser receives when loading a page. It brings server response headers, cookie details and external resources into one report. Run it after configuring a web server, connecting a CDN or releasing a new site version to see which settings need attention without inspecting every response manually in DevTools.

HTTPS, CSP and security headers

The scanner checks HTTPS, HSTS and mixed content, along with X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers. A separate category covers Content Security Policy, showing detected directives and findings about unsafe-inline and unsafe-eval. Headers come from the main page response after redirects, so the result describes the URL actually loaded.

Cookies, CORS and external resources

The cookie check shows whether Secure, HttpOnly and SameSite attributes are present. The report includes cookie names, domains and attributes without their values. For external resources, the service analyses Subresource Integrity and observed CORS settings. These details help distinguish your site’s settings from those of connected third-party resources.

How to use audit results

Start with high-priority recommendations, then open the relevant category and review the collected evidence. The overall score helps compare runs, but specific findings and application context matter more. After making changes, audit the same page again and download the report as JSON. Results describe one page load and do not establish the security of business logic or authentication flows.

FAQ

Security audit questions

A passive check of the loaded page configuration. Findings require context and do not replace a penetration test.

What does the security scanner check?
It audits HTTPS setup, security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy), cookie flags, CORS configuration, and Subresource Integrity. The scanner is passive — no attack traffic is sent to your site.
How often should I run a security audit?
Run after every major deploy, infrastructure change, or modification to authentication and headers. For production sites, a monthly audit catches regressions before they become incidents.
Does this replace a full penetration test?
No. The scanner catches configuration gaps and missing hardening, but a penetration test examines business logic, authentication flows, and deeper attack surfaces that automated scans cannot cover.
Related services

What to check next to this service

Adjacent checks help reveal nearby causes across speed, code, accessibility, SEO, and page state after user scenarios.

HTML validation

Check page structure, validity, semantics, and required meta tags.

Open

Accessibility (a11y)

WCAG audit: contrast, alt text, landmarks, aria attributes, and keyboard navigation. Includes fixes and examples.

Open

JS scanner

JavaScript performance, code coverage during load, bundle composition, and third-party scripts.

Open

CSS audit

Stylesheet size, unused selectors, duplicates, and specificity explosion. See what can be removed safely.

Open

Check your page’s security settings

Enter a URL to see check results and understand which settings need attention.

Run security audit
Milten

A platform for checking speed, SEO, and frontend quality.

Performance

  • Speed scanner
  • INP debugger
  • BF cache
  • SSR check

Code

  • HTML Scanner
  • Design tokens
  • A11Y audit
  • Memory leaks

Company

  • Docs
  • Blog
  • Contact
© 2026 MiltenTermsPrivacy
Cookies

We use cookies

We use cookies to give you a better experience on our site. You can learn more about how we use cookies in our privacy policy.