This inspects real HTTP response headers and the live TLS certificate of a public URL. It never sends repeated bursts of requests to test rate limiting on a real third-party site (that would be indistinguishable from an abuse probe); rate-limit signals are read passively from response headers only.

Security Analyzer

Enter any public website URL to check HTTPS, CSP, security headers, HSTS, and its TLS certificate.

Try: