Missing security headers
No Content-Security-Policy, no HSTS, no X-Frame-Options. Browsers stop protecting your visitors and you become an easy target for clickjacking and injection.
Security Shield runs 10 automated passive tests against any domain and returns a single A to F grade. Headers, TLS, cookies, open ports, DNS and more, checked from the outside, with zero impact on your servers.
Free headers check on 1 site, no card required. All 10 tests from £29/mo.
One failing check is dragging this domain down. Fix the open port and it moves to an A.
Your site can look perfectly healthy and still be leaking risk. These are the misconfigurations Security Shield catches on every scan.
No Content-Security-Policy, no HSTS, no X-Frame-Options. Browsers stop protecting your visitors and you become an easy target for clickjacking and injection.
Outdated protocol versions, weak ciphers, or a certificate quietly counting down to expiry. When it lapses, every visitor hits a full-page browser warning.
Session cookies served without Secure, HttpOnly, or SameSite. That is the difference between a private session and one that can be read or hijacked.
A single script or image loaded over HTTP breaks the padlock, triggers console warnings, and gives attackers a way in on an otherwise secure page.
A database, admin panel, or debug port left listening on the public internet. You will not see it in your browser, but a scanner will find it in seconds.
Landing on a DNSBL blocklist quietly routes your email to spam and flags your site in security tools, and most teams only notice weeks after the damage is done.
Add a domain and get an A to F security grade with no setup.
Every scan runs the same 10 tests. Each one passes, warns or fails, and together they produce the letter grade for the domain.
CSP, HSTS, X-Frame-Options, X-Content-Type-Options and the rest, scored against modern best practice.
Protocol versions, cipher strength and certificate validity checked from the outside in.
Every cookie inspected for Secure, HttpOnly and SameSite attributes.
Detects insecure HTTP assets loaded on HTTPS pages that break the padlock.
Passive discovery of services listening on the public internet that should not be.
Checks your domain and mail server against known spam and abuse blocklists.
Identifies the software and versions you expose, so you know what you are advertising.
Registration status, expiry dates and ownership signals for the domain itself.
SPF, DKIM and DMARC records validated so your email cannot be trivially spoofed.
Maps the subdomains attached to your domain so nothing forgotten stays exposed.
Security tools usually bury you in raw findings. Security Shield rolls all 10 results into a grade from A to F, with no E, so anyone from a developer to a client can read it instantly. A passing header check nudges you up. A failing open-port check drags you down.
Clean across every test. Nothing material to fix.
Strong overall with one or two warnings to tidy up.
Real gaps present. Worth prioritising this month.
Multiple weaknesses exposed to the public internet.
Serious failures. Fix before they become an incident.
Security Shield needs nothing installed. You add a domain, we do the rest.
Enter a site once. No agent, no DNS changes, no code to install. Security Shield works entirely from the outside.
PulseStack inspects headers, TLS, cookies, ports, DNS and more from our checking network, without touching or loading your servers.
Each test passes, warns or fails and rolls up into a single letter grade, so the whole team understands where a site stands at a glance.
Re-scans run on a schedule. If your grade drops or a check starts failing, you are alerted before it becomes an incident.
Security Shield never attacks your site. It inspects what you already expose to the public, the same information any visitor or scanner can see, and reports it back. No exploit attempts, no attack traffic, no risk of taking your own site down.
Pair Security Shield with uptime and SEO monitoring on the same platform.
Security Shield lives inside PulseStack, so the same account watches your uptime, endpoints and DNS too.
Status, response time and content of any URL.
Confirm expected text is present, or flag banned words.
Reachability of any host on the network.
Watch a specific service port stay open or closed.
Endpoint checks with custom request headers.
Cron and background jobs report in, or you hear about it.
Records resolve to the values you expect.
Never lose a domain to a missed renewal.
It is not a scanner suite and it is not a pen test. It is a continuous, plain-English grade you can actually keep an eye on.
The default for most sites.
Continuous passive monitoring.
Deep, but a snapshot in time.
Security Shield is not a replacement for a full penetration test. It is the continuous early-warning layer that keeps the basics honest between them.
Run a Security Shield scan across every client site and hand over a clean A to F grade in your reports. Spot the risky sites before the client does.
One dashboard for headers, TLS, DNS and cookie hygiene across your whole estate. Catch a dropped grade the moment a deploy weakens a config.
Ship with confidence. A passive external grade tells you exactly which header, cipher or cookie flag is missing, with no infrastructure access required.
Alerts fire on failure and again on recovery, after a consecutive-failure threshold you set.
No. Every one of the 10 tests is passive. We inspect what your site already exposes to the public internet, we never attempt to exploit, break in or send attack traffic. It is a health check, not a pen test.
Each of the 10 tests passes, warns or fails, and those results roll up into a single letter grade from A to F, with no E. An A means clean across the board, an F means several serious checks are failing.
The free plan runs the security headers check on one site so you can see the format and value straight away. All 10 tests unlock from £29 per month on the Starter Security Shield plan.
Security headers, TLS configuration, cookie flags, mixed content, open ports, DNSBL blacklist, tech fingerprint, domain and WHOIS, DNS security covering SPF, DKIM and DMARC, and subdomain discovery.
No. Security Shield works entirely from the outside. There is no agent, no DNS change and no code to add. You enter a domain and we do the rest from our checking network.
Scans run on a schedule and you are alerted whenever a grade drops or a check starts failing. Alerts fire on failure and again on recovery, after a configurable consecutive-failure threshold, across all eight native channels.
Run the security headers check free on one site, then unlock all 10 tests from £29 a month. No agent, no risk, no card to start.