Security Shield

Grade your site’s security before an attacker does it for you

Security Shield runs 10 automated passive tests against any domain and returns a single A to F grade. Headers, TLS, cookies, open ports, DNS and more, checked from the outside, with zero impact on your servers.

Free headers check on 1 site, no card required. All 10 tests from £29/mo.

acme-store.co.uk
Security Shield
BGrade
10 passive tests7 pass / 2 warn / 1 fail
A
B
C
D
F

One failing check is dragging this domain down. Fix the open port and it moves to an A.

Security headers
WARN
TLS configuration
PASS
Cookie flags
PASS
Mixed content
PASS
Open ports
FAIL
DNS security (SPF/DKIM/DMARC)
WARN
10
passive tests per scan
A to F
single-letter grade
£0
headers check on 1 site
Zero
impact on your servers
What silently goes wrong

The security gaps you never see in a browser

Your site can look perfectly healthy and still be leaking risk. These are the misconfigurations Security Shield catches on every scan.

01

Missing security headers

No Content-Security-Policy, no HSTS, no X-Frame-Options. Browsers stop protecting your visitors and you become an easy target for clickjacking and injection.

02

Weak or expiring TLS

Outdated protocol versions, weak ciphers, or a certificate quietly counting down to expiry. When it lapses, every visitor hits a full-page browser warning.

03

Cookies without flags

Session cookies served without Secure, HttpOnly, or SameSite. That is the difference between a private session and one that can be read or hijacked.

04

Mixed content on HTTPS

A single script or image loaded over HTTP breaks the padlock, triggers console warnings, and gives attackers a way in on an otherwise secure page.

05

Exposed ports and services

A database, admin panel, or debug port left listening on the public internet. You will not see it in your browser, but a scanner will find it in seconds.

06

Domain on a blacklist

Landing on a DNSBL blocklist quietly routes your email to spam and flags your site in security tools, and most teams only notice weeks after the damage is done.

See your grade in under a minute

Add a domain and get an A to F security grade with no setup.

The 10 tests

Ten passive checks, one clear grade

Every scan runs the same 10 tests. Each one passes, warns or fails, and together they produce the letter grade for the domain.

01

Security headers

CSP, HSTS, X-Frame-Options, X-Content-Type-Options and the rest, scored against modern best practice.

02

TLS configuration

Protocol versions, cipher strength and certificate validity checked from the outside in.

03

Cookie flags

Every cookie inspected for Secure, HttpOnly and SameSite attributes.

04

Mixed content

Detects insecure HTTP assets loaded on HTTPS pages that break the padlock.

05

Open ports

Passive discovery of services listening on the public internet that should not be.

06

DNSBL blacklist

Checks your domain and mail server against known spam and abuse blocklists.

07

Tech fingerprint

Identifies the software and versions you expose, so you know what you are advertising.

08

Domain / WHOIS

Registration status, expiry dates and ownership signals for the domain itself.

09

DNS security

SPF, DKIM and DMARC records validated so your email cannot be trivially spoofed.

10

Subdomain discovery

Maps the subdomains attached to your domain so nothing forgotten stays exposed.

How grading works

From a wall of results to one letter

Security tools usually bury you in raw findings. Security Shield rolls all 10 results into a grade from A to F, with no E, so anyone from a developer to a client can read it instantly. A passing header check nudges you up. A failing open-port check drags you down.

  • One grade per domain, refreshed on every scan
  • Drill into any test to see exactly what failed and why
  • Track the grade over time as you fix issues
A

Clean across every test. Nothing material to fix.

B

Strong overall with one or two warnings to tidy up.

C

Real gaps present. Worth prioritising this month.

D

Multiple weaknesses exposed to the public internet.

F

Serious failures. Fix before they become an incident.

How it works

Four steps, no infrastructure access

Security Shield needs nothing installed. You add a domain, we do the rest.

1

Add your domain

Enter a site once. No agent, no DNS changes, no code to install. Security Shield works entirely from the outside.

2

We run 10 passive tests

PulseStack inspects headers, TLS, cookies, ports, DNS and more from our checking network, without touching or loading your servers.

3

Get an A to F grade

Each test passes, warns or fails and rolls up into a single letter grade, so the whole team understands where a site stands at a glance.

4

Alerts on every change

Re-scans run on a schedule. If your grade drops or a check starts failing, you are alerted before it becomes an incident.

Passive by design

A health check, not a penetration test

Security Shield never attacks your site. It inspects what you already expose to the public, the same information any visitor or scanner can see, and reports it back. No exploit attempts, no attack traffic, no risk of taking your own site down.

  • Reads public responses only, never sends exploit payloads
  • Safe to run against production continuously
  • No agent, no credentials, no server load
security-shield · acme-store.co.uk
$ pulsestack security scan acme-store.co.uk
Running 10 passive tests (read-only)...
Security headers[WARN] CSP missing
TLS configuration[PASS] TLS 1.3
Cookie flags[PASS]
Mixed content[PASS]
Open ports[FAIL] 5432 exposed
DNSBL blacklist[PASS]
Tech fingerprint[PASS]
Domain / WHOIS[PASS]
DNS security[WARN] no DMARC
Subdomain discovery[PASS] 6 found
Overall grade: B · 7 pass, 2 warn, 1 fail
Everything included

What you get with Security Shield

All 10 passive security tests
A single A to F grade per domain
Security headers scored to best practice
TLS protocol and cipher inspection
Certificate validity tracking
Cookie flag auditing
Mixed content detection
Public open-port discovery
DNSBL blacklist checks
SPF, DKIM and DMARC validation
Subdomain mapping
Alerts on grade drops and recovery

Security is one part of the picture

Pair Security Shield with uptime and SEO monitoring on the same platform.

One platform

Eight monitor types alongside your security grade

Security Shield lives inside PulseStack, so the same account watches your uptime, endpoints and DNS too.

HTTP

Status, response time and content of any URL.

Keyword

Confirm expected text is present, or flag banned words.

TCP Ping

Reachability of any host on the network.

Port

Watch a specific service port stay open or closed.

API

Endpoint checks with custom request headers.

Heartbeat

Cron and background jobs report in, or you hear about it.

DNS

Records resolve to the values you expect.

Domain Expiry

Never lose a domain to a missed renewal.

An honest comparison

Where Security Shield fits

It is not a scanner suite and it is not a pen test. It is a continuous, plain-English grade you can actually keep an eye on.

Doing nothing

The default for most sites.

  • No visibility of exposure
  • Find out from an incident
  • Grade unknown
  • £0 and zero protection

Security Shield

Best fit

Continuous passive monitoring.

  • 10 tests, one A to F grade
  • Re-scans on a schedule
  • Alerts when the grade drops
  • From £0 on 1 site

A one-off pen test

Deep, but a snapshot in time.

  • Thorough and manual
  • Actively probes for exploits
  • True the day it is done
  • Costly and infrequent

Security Shield is not a replacement for a full penetration test. It is the continuous early-warning layer that keeps the basics honest between them.

Who it is for

Built for the people who answer for the site

Agencies

Run a Security Shield scan across every client site and hand over a clean A to F grade in your reports. Spot the risky sites before the client does.

In-house teams

One dashboard for headers, TLS, DNS and cookie hygiene across your whole estate. Catch a dropped grade the moment a deploy weakens a config.

Developers

Ship with confidence. A passive external grade tells you exactly which header, cipher or cookie flag is missing, with no infrastructure access required.

Eight native alert channels

Hear about a dropped grade wherever you work

Alerts fire on failure and again on recovery, after a consecutive-failure threshold you set.

EmailSMSSlackMicrosoft TeamsDiscordPagerDutyTelegramWebhooks
FAQ

Questions about Security Shield

Is Security Shield a penetration test?

No. Every one of the 10 tests is passive. We inspect what your site already exposes to the public internet, we never attempt to exploit, break in or send attack traffic. It is a health check, not a pen test.

What does the A to F grade actually mean?

Each of the 10 tests passes, warns or fails, and those results roll up into a single letter grade from A to F, with no E. An A means clean across the board, an F means several serious checks are failing.

Which tests does the free plan include?

The free plan runs the security headers check on one site so you can see the format and value straight away. All 10 tests unlock from £29 per month on the Starter Security Shield plan.

What are the 10 tests?

Security headers, TLS configuration, cookie flags, mixed content, open ports, DNSBL blacklist, tech fingerprint, domain and WHOIS, DNS security covering SPF, DKIM and DMARC, and subdomain discovery.

Do I need to install anything on my server?

No. Security Shield works entirely from the outside. There is no agent, no DNS change and no code to add. You enter a domain and we do the rest from our checking network.

How often does it re-scan, and how am I alerted?

Scans run on a schedule and you are alerted whenever a grade drops or a check starts failing. Alerts fire on failure and again on recovery, after a configurable consecutive-failure threshold, across all eight native channels.

Find out your grade today

Run the security headers check free on one site, then unlock all 10 tests from £29 a month. No agent, no risk, no card to start.