Free
See where you stand
$0 forever
- All 20+ checks
- Your score and the 3 most urgent problems
- 5 checks a month on 1 website
Type your address. In about 90 seconds you will see what is wrong and what to send your developer.
Needs attention. Two problems should be fixed this week.
62/100
Fix this week 2
This month 1
Can wait 1
This is a sample. Run the check above and your own result appears in this window.
For your developer
Subject: Security fixes for example-shop.com
Hi, a security scan found the issues below. Could you send me a quote and a date for the fixes?
/backup-full.zip is publicly accessible (HTTP 200, 48 MB). Remove it from the web root and deny *.zip, *.sql, *.tar.gz in the server config.Outdated plugins: slider-pro 2.1.0 (known vulnerability, fixed in 2.4.3), plus two more listed in the attached report. Update and retest.No DMARC record. Add _dmarc TXT "v=DMARC1; p=quarantine; rua=mailto:..." once SPF and DKIM pass.Missing Content-Security-Policy and X-Content-Type-Options: nosniff. Add at the web server level.Evidence and full details are in the attached report. Thanks!
Your certificate is valid, is not about to expire, and every page loads over a secure connection.
We compare your WordPress, plugin and theme versions with public lists of known security holes.
We test whether your forms and links accept input they should refuse.
Old backups, configuration files and admin pages that anyone could open or download.
Whether your domain stops strangers from sending mail in your name.
Hidden scripts, spam links and redirects that hacked sites often carry without the owner knowing.
Test sites, old subdomains and services that were left open to the internet.
Settings that stop other sites from hijacking a login session or framing your pages.
See where you stand
$0 forever
Keeps an eye on your site
$12 /mo
Checks your site on a schedule and emails you when something changes. Costs less than an hour of a developer's time a month.
For agencies and freelancers
$29 /mo
Send clients security reports with your own logo and add them to your maintenance plan.
Need it just once? A full scan of one website with the complete report costs $9, no subscription.
For $3 more, Pro watches it for a whole month.
No. Type your address and read the report. It is written for the person who owns the business. The technical part goes into a separate brief for your developer.
No. The checks are designed not to change anything on your site, and they are paced so your visitors will not notice.
No. ShieldWave only looks at what anyone on the internet can see. That is also what attackers see, which is the point.
Open the report. It tells you what to fix this week, this month and later. Forward the developer brief to whoever looks after your site. If nobody does, write to me: at ENSOMEDIA I build and maintain websites, and I will quote the fixes.
Free checkers usually test one thing, such as the SSL certificate, and show the result in technical terms. ShieldWave runs more than 20 checks at once, connects findings that make each other worse, and explains what they mean for your business.
Yes. Five checks a month for one website, no card needed. You see your score and your three most urgent problems. You pay only if you want the full report, more sites or scheduled checks.
Yes, from your account settings. Your plan stays active until the end of the period you already paid for.
It works with any public website. WordPress sites get extra checks for the core, plugins and themes, because that is where most WordPress problems start.
No, and we will not pretend it does. In a pentest a specialist spends days trying to break in. ShieldWave catches the common holes that automated bots look for, in about 90 seconds.
They stay in your account and we do not share them with anyone. You can ask us to delete your data at any time. The details are in our privacy policy.