security.txt builder
A signed contract with the security research community. Host the result at /.well-known/security.txt.
Inputs
/.well-known/security.txt
ValidContact: mailto:[email protected] Expires: 2027-08-12T18:59:20.792Z Preferred-Languages: en
Save as security.txt (no extension change) and serve at https://yourdomain/.well-known/security.txt withContent-Type: text/plain; charset=utf-8.
Why ship a security.txt? Without it, a researcher who finds a bug has to guess your disclosure channel. Half the time they give up and the bug gets sold to someone less friendly. Pair with a vulnerability-disclosure policy (VDP) and you'll catch issues months earlier.
Keep hardening your site
This is one check of many. Run the rest — every tool is free, no account.
Security headers scan
Grade your live response headers
TLS certificate scan
Grade chain, expiry, and key strength
Security headers builder
Emit a ready-to-paste header block
CSP analyzer
Grade your Content-Security-Policy
Cookie security audit
Check Secure, HttpOnly, SameSite
Mixed-content scanner
Find http:// assets on https pages
Open-redirect detector
Probe redirect params for abuse
HSTS preload checker
Grade against Chrome's preload list