Website Security & SSL Expiry Checker — Headers, HTTPS, A–F avatar

Website Security & SSL Expiry Checker — Headers, HTTPS, A–F

Pricing

$5.00 / 1,000 site checkeds

Go to Apify Store
Website Security & SSL Expiry Checker — Headers, HTTPS, A–F

Website Security & SSL Expiry Checker — Headers, HTTPS, A–F

Grade websites A–F on security headers, TLS certificate validity & expiry, HTTPS redirect and cookie flags; returns the single most important fix per site. One normal visit per site, no scanning.

Pricing

$5.00 / 1,000 site checkeds

Rating

0.0

(0)

Developer

Joshua Pole

Joshua Pole

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

How secure does a website look from the outside? Paste a list of domains and get an A–F grade per site — security headers, TLS certificate, HTTPS redirect, cookie flags and version leaks — plus the one fix that matters most, ready to hand to a developer.

✅ A–F grade + 0–100 score  ·  ✅ Expiring & broken certificates  ·  ✅ One prioritised fix per site  ·  ✅ 5,000 sites per run  ·  ✅ One normal visit per site — no scanning


⚡ See it in 5 seconds

// input
{ "domains": ["acme-shop.com"] }
// output
{
"domain": "acme-shop.com",
"grade": "D",
"score": 52,
"main_fix": "Renew the TLS certificate on acme-shop.com now — it expires on 2026-10-13. Enable auto-renewal.",
"cert_days_left": 12,
"issues": [
"TLS certificate expires in 12 days",
"Missing HSTS header",
"No clickjacking protection (X-Frame-Options / frame-ancestors)",
"Server header leaks version: Apache/2.4.41"
]
}

A grade your client understands, and a fix your developer can paste.


🎯 Who uses this

You areYou use it to
Web agency / web builderCheck every site you host or built, and fix weak spots before a client — or an auditor — finds them.
MSP / IT service providerMonthly hygiene report across all client sites; catch certificates before they expire.
Security consultantInstant external baseline for an assessment or a proposal, with concrete remediation.
Sales / lead generationFind companies with an F-grade website — a specific, verifiable reason to start a conversation.
SEO / marketing teamsHTTPS redirects and valid certificates affect trust signals and browser warnings.

🔍 What it checks

AreaDetails
TLS certificateValid & trusted · expired · self-signed · hostname mismatch · days until expiry · issuer · negotiated TLS version
HTTPSSite reachable over HTTPS · HTTP → HTTPS redirect
Security headersStrict-Transport-Security (incl. max-age) · Content-Security-Policy · clickjacking protection (X-Frame-Options or CSP frame-ancestors) · X-Content-Type-Options · Referrer-Policy · Permissions-Policy
Information leakageServer header with version number · X-Powered-By
CookiesCookies set on the landing page without Secure, HttpOnly or SameSite

Input is forgiving: https://www.acme-shop.com/contact, ACME-SHOP.COM and info@acme-shop.com all work. Duplicates are removed.


🚦 Grades

GradeScoreMeaning
🟢 A90–100Strong baseline.
🟢 B80–89Good — a few missing headers.
🟡 C65–79Basic protection, clear gaps.
🟠 D50–64Weak — multiple important protections missing.
🔴 F0–49Broken certificate, no HTTPS, or almost no protection.
⚪ blocked–Bot protection (403/429/503) hid the real page — certificate fields still filled, not billed.
⚪ error–Site not reachable or invalid — not billed.

What weighs most

ProblemPenalty
No working HTTPS−60
Invalid / expired certificate−50
TLS 1.0 / 1.1 negotiated−30
Certificate expires within 14 days−20
No HTTP → HTTPS redirect · missing HSTS · missing CSP−15 each
No clickjacking protection−10
Certificate expires within 30 days · short HSTS · nosniff · Referrer-Policy · insecure cookies−5 each
Version leaks · Permissions-Policy−3 each

main_fix always picks the highest-impact problem first: HTTPS → certificate → protocol → expiry → redirect → HSTS → CSP → clickjacking → the rest.


📊 Example: a portfolio run

Dataset → Overview view:

sitegradescorecert days leftmain_fix
old-portal.acme.com🔴 F0-31 ❌Replace the TLS certificate (certificate has expired) — browsers show a security warning.
contoso-bakery.nl🔴 F3285Redirect http://contoso-bakery.nl to https://contoso-bakery.nl with a 301.
fabrikam.net🟠 D5212Renew the TLS certificate now — it expires on 2026-10-13. Enable auto-renewal.
northwind.io🟡 C7464Add header — Content-Security-Policy: default-src 'self'; frame-ancestors 'self'
litware.com🟢 B82142Raise HSTS to: Strict-Transport-Security: max-age=31536000; includeSubDomains
adatum.eu🟢 A9259Add header — Permissions-Policy: geolocation=(), camera=(), microphone=()
wingtip.co⚪ blocked–58bot protection returned HTTP 403 — not billed

Key-value store → SUMMARY — worst first, plus every certificate expiring within 30 days:

{
"sites": 7,
"grades": { "A": 1, "B": 1, "C": 1, "D": 1, "F": 2, "blocked": 1 },
"fix_first": [
{ "domain": "old-portal.acme.com", "grade": "F", "score": 0, "main_fix": "Replace the TLS certificate …" },
{ "domain": "contoso-bakery.nl", "grade": "F", "score": 32, "main_fix": "Redirect http:// … to https:// … with a 301." },
{ "domain": "fabrikam.net", "grade": "D", "score": 52, "main_fix": "Renew the TLS certificate now …" }
]
}

(Example domains are fictional; the grades and fixes are real outputs of this Actor on real websites.)


📥 Input

FieldTypeDefaultDescription
domainsstring[]—Required. Domains or URLs. Max 5,000 per run.
concurrencyinteger10Sites checked in parallel (1–30).
timeoutSecsinteger15Per-request timeout.

📤 Output fields

FieldDescription
domainNormalised host name.
grade / scoreA–F (or blocked / error) and 0–100.
main_fixThe single most important fix.
issuesEvery problem found, in plain English.
final_url / http_statusWhere the HTTPS visit ended up, and its status code.
https_redirectDoes http:// redirect to https://?
tls_versionNegotiated protocol (e.g. TLSv1.3).
cert_valid · cert_error · cert_issuer · cert_expires · cert_days_leftCertificate trust, problem, issuer, expiry date and days left.
headers_present / headers_missingWhich security headers are (not) set.
server / x_powered_byTechnology headers, if exposed.
insecure_cookiesCookies missing Secure / HttpOnly / SameSite.
errorWhy a site could not be graded.
checked_atUTC timestamp.

Export as CSV, Excel, JSON, XML or HTML, or send it to Google Sheets, Zapier, Make or n8n.


🔌 Use it via API

Python

from apify_client import ApifyClient
client = ApifyClient("YOUR_API_TOKEN")
run = client.actor("securityzenkai/website-security-checker").call(
run_input={"domains": ["acme-shop.com", "northwind.io"]}
)
for row in client.dataset(run["defaultDatasetId"]).iterate_items():
print(f'{row["domain"]}: {row["grade"]} — {row["main_fix"]}')

JavaScript

import { ApifyClient } from "apify-client";
const client = new ApifyClient({ token: "YOUR_API_TOKEN" });
const run = await client.actor("securityzenkai/website-security-checker").call({
domains: ["acme-shop.com", "northwind.io"],
});
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.filter((r) => r.cert_days_left !== null && r.cert_days_left < 30)
.forEach((r) => console.log(`${r.domain}: certificate expires in ${r.cert_days_left} days`));

Schedule it weekly in Apify and you have a free-standing certificate-expiry monitor for all your sites.


💰 Pricing

$5 per 1,000 sites checked ($0.005 per site). Unreachable sites and sites hidden behind bot protection are free. No subscription, no seats.


🛡️ Non-intrusive by design

Per site, this Actor does exactly what a browser does when someone types the address: one HTTPS request, one HTTP request (to see whether it redirects) and the normal TLS handshake. No port scans, no directory brute-forcing, no attack payloads, no forced legacy-protocol handshakes. Safe to run on any list of public websites.

⚠️ What it does not do

  • Not a vulnerability scanner. It grades the visible security configuration, not the application code (no SQLi/XSS testing).
  • Only the landing page. Headers and cookies are read from the page the domain lands on; other pages can differ.
  • No full TLS audit. It reports the negotiated protocol, not every supported cipher or legacy protocol.
  • Bot protection can hide the real site. Those sites come back as blocked (free) rather than with a misleading grade.
  • CSP quality isn't scored. A present CSP counts; whether it's strict enough is up to you.

❓ FAQ

Why is a missing HSTS header so important? Without HSTS, a visitor's first request can be silently downgraded to plain HTTP on a hostile network (public Wi-Fi), exposing logins and cookies.

My site redirects to HTTPS in JavaScript — why "no redirect"? Only a server-side redirect (301/302) protects the first request. A JavaScript redirect happens after the insecure page is already loaded.

What counts as clickjacking protection? Either X-Frame-Options: DENY/SAMEORIGIN or a CSP with frame-ancestors. Without one, your pages can be framed invisibly on a malicious site.

Can I use this to monitor certificate expiry? Yes — schedule it weekly and filter on cert_days_left < 30, or read the SUMMARY record, which lists every certificate expiring within 30 days.

Do I need API keys? No.