full check
Run the full check on your site
Everything in the quick check, plus leaked keys in your code, files that shouldn't be public and your database settings. Enter your site, add the tag we give you to your home page (your AI can do it for you), then run it.
what it adds
- Keys and passwords in your site's code
- Files like .env and .git that shouldn't be public
- Your Supabase or Firebase setup
- Whether other sites can read your pages as your logged in users
- Server version info your site gives out
Plus everything in the quick check: https, headers and cookies.
Good to know
- Your tag is made from a random key saved in this browser, so run full checks from the same one. Leave the tag in and every full check after that is one click.
- The tag is public and holds no secret. If you'd rather not touch your code, a DNS TXT record works too.
- Same as the quick check, it only reads pages like a browser does: no forms, no logins, and 30 requests at most.
- Checking a client's site? Add the tag with their go ahead, or send them the line to add.
Just want a grade? Run the quick check. No tag needed.