Is your website safe? Get an answer in plain language.

Type your address. In about 90 seconds you will see what is wrong and what to send your developer.

Free, no account, no password. Your site keeps running as usual.

Reportsexample-shop.com

Download PDFSend to developer

example-shop.com

Needs attention. Two problems should be fixed this week.

62/100

Fix this week 2

  • A full backup of your site can be downloaded by anyone who guesses its address. It contains your customer database.Exposed files
  • Three plugins are out of date. One of them has a publicly known security hole that bots actively look for.WordPress & plugins

This month 1

  • Anyone can send email that looks like it came from your shop. Customers could receive fake invoices in your name.Email

Can wait 1

  • Your site does not tell browsers to block content from other sites. Low risk on its own, worth adding with the next update.Browser protection

This is a sample. Run the check above and your own result appears in this window.

For your developer

To your developer

Subject: Security fixes for example-shop.com

Hi, a security scan found the issues below. Could you send me a quote and a date for the fixes?

  • /backup-full.zip is publicly accessible (HTTP 200, 48 MB). Remove it from the web root and deny *.zip, *.sql, *.tar.gz in the server config.
  • Outdated plugins: slider-pro 2.1.0 (known vulnerability, fixed in 2.4.3), plus two more listed in the attached report. Update and retest.
  • No DMARC record. Add _dmarc TXT "v=DMARC1; p=quarantine; rua=mailto:..." once SPF and DKIM pass.
  • Missing Content-Security-Policy and X-Content-Type-Options: nosniff. Add at the web server level.

Evidence and full details are in the attached report. Thanks!

The questions an attacker asks about your site, answered before they ask.

  • Your certificate is valid, is not about to expire, and every page loads over a secure connection.

  • We compare your WordPress, plugin and theme versions with public lists of known security holes.

  • We test whether your forms and links accept input they should refuse.

  • Old backups, configuration files and admin pages that anyone could open or download.

  • Whether your domain stops strangers from sending mail in your name.

  • Hidden scripts, spam links and redirects that hacked sites often carry without the owner knowing.

  • Test sites, old subdomains and services that were left open to the internet.

  • Settings that stop other sites from hijacking a login session or framing your pages.

A simulation of typical bot traffic. This is an ordinary day for an ordinary business website.Drag to turn

Start free. Pay when you want the full picture.

Free

See where you stand

$0 forever

  • All 20+ checks
  • Your score and the 3 most urgent problems
  • 5 checks a month on 1 website

Pro

Keeps an eye on your site

$12 /mo

Checks your site on a schedule and emails you when something changes. Costs less than an hour of a developer's time a month.

  • The full report, with how to fix each problem
  • Automatic checks and an email when something changes
  • A brief for your developer, ready to send
  • Up to 25 websites, unlimited checks
  • PDF reports and GDPR mapping

Enterprise

For agencies and freelancers

$29 /mo

Send clients security reports with your own logo and add them to your maintenance plan.

  • Everything in Pro, unlimited websites
  • Reports with your own logo
  • PCI-DSS, ISO 27001 and NIS2 mapping
  • Up to 10 team members
  • Priority support

Need it just once? A full scan of one website with the complete report costs $9, no subscription.

For $3 more, Pro watches it for a whole month.

Questions owners ask us

Do I need to be technical to use this?

No. Type your address and read the report. It is written for the person who owns the business. The technical part goes into a separate brief for your developer.

Will the scan slow down or break my site?

No. The checks are designed not to change anything on your site, and they are paced so your visitors will not notice.

Do you need my password or hosting access?

No. ShieldWave only looks at what anyone on the internet can see. That is also what attackers see, which is the point.

The scan found something. What now?

Open the report. It tells you what to fix this week, this month and later. Forward the developer brief to whoever looks after your site. If nobody does, write to me: at ENSOMEDIA I build and maintain websites, and I will quote the fixes.

How is this different from free online checkers?

Free checkers usually test one thing, such as the SSL certificate, and show the result in technical terms. ShieldWave runs more than 20 checks at once, connects findings that make each other worse, and explains what they mean for your business.

Is the free plan really free?

Yes. Five checks a month for one website, no card needed. You see your score and your three most urgent problems. You pay only if you want the full report, more sites or scheduled checks.

Can I cancel anytime?

Yes, from your account settings. Your plan stays active until the end of the period you already paid for.

Does it work with my website?

It works with any public website. WordPress sites get extra checks for the core, plugins and themes, because that is where most WordPress problems start.

Does this replace a penetration test?

No, and we will not pretend it does. In a pentest a specialist spends days trying to break in. ShieldWave catches the common holes that automated bots look for, in about 90 seconds.

What happens to my scan results?

They stay in your account and we do not share them with anyone. You can ask us to delete your data at any time. The details are in our privacy policy.

Got two minutes? Check your site.