LetCheck
LetChecksSecurity Scanner
FREE · NO LOGIN REQUIRED · v1.0

Scan any website or app.
Know its risk in 60 seconds.

LetCheck runs a deep, non-intrusive audit covering security headers, SSL, SEO, performance, WHOIS ownership, hosting provider, tech stack, and email DNS — then explains everything in plain language.

no login · no exploitation · no intrusion · read-only defensive scan

Sign in or register free to run a scan

Free · score + top 3 alerts · instant
GHS 149Full report · AI briefing · PDF
0+
Websites Scanned
0+
Issues Detected
0+
Check Categories
0s
Average Scan Time
// live_report

Professional-grade
security intelligence
in under a minute

Every scan produces a structured audit report with severity-ranked findings, AI-generated executive briefing, SSL grading, and full infrastructure intelligence.

SSL grade A+ through F — same methodology as SSL Labs
Findings ranked critical → high → medium → low
AI executive briefing ready to share with stakeholders
WHOIS, hosting, ASN, tech stack, third-party map
letchecks.com
Completed · just now
CLEAN
74/100
A
SSL Grade
Excellent
423ms
TTFB
Moderate
Security
62
SSL
91
SEO
85
Performance
73
TLS 1.3 + HSTS enforced
No malware detected
Missing Content-Security-Policy
No DMARC record found
3 outdated libraries detected
Full report availableGHS 149 →
// finding_distribution

Every finding ranked
by risk level

23findings
Critical
3
High
6
Medium
9
Low
5
// performance_waterfall

Performance metrics
at a glance

DNS lookup
12ms
TCP connect
28ms
TLS handshake
45ms
TTFB
423ms
Download
318ms
Total load: 826ms · 1.2MB · 47 requests

// scan_modules

Nine inspection layers, one report.

Every scan covers 30+ checks across 9 security and quality domains, completed in under 60 seconds.

Security headers

HSTS, CSP, X-Frame, X-Content-Type, Referrer-Policy, Permissions-Policy, server disclosure, mixed content.

SSL / TLS

Certificate validity, expiry, issuer, self-signed detection, A+ grading, HTTPS redirect hygiene.

SEO

Title, meta description, headings, canonical, Open Graph, Twitter cards, JSON-LD, robots.txt, sitemap.

Performance

TTFB, response time, payload size, compression (gzip/br), caching headers, external script count.

Accessibility

Viewport, language attribute, alt text coverage, semantic structure, favicon, manifest, keyboard traps.

Email DNS

SPF, DMARC, MX records — email spoofing and phishing attack surface analysis.

Domain & WHOIS

Registrar, registrant, country, domain age, expiry date, nameservers via RDAP/WHOIS.

Hosting & IP

Resolved IP, ISP, ASN, city/country geolocation, reverse DNS, CDN detection.

AI briefing

GPT-4o executive summary: overall posture, top 3 priorities to fix, what's already done well.

// how_it_works

From URL to full report in 3 steps

01

Enter any URL

Website, web app, mobile app URL, or IP address. We resolve and normalise it automatically.

02

60-second deep scan

30+ checks run in parallel: SSL, headers, SEO, DNS, WHOIS, tech stack, AI briefing.

03

Receive your report

Score, grade, ranked findings, and AI summary online instantly. Full PDF via email.

// ai_engine

An analyst that explains, prioritizes, and recommends.

Every scan is interpreted by an AI engine that turns raw findings into an executive briefing, a prioritized action list, and concrete remediation guidance — written in plain language.

  • Risk-ranked findings with business impact in plain language
  • Executive summary ready to share with non-technical stakeholders
  • Concrete remediation steps engineers can ship immediately
  • Identifies what's already done well — not just what's broken
letcheck.log
> GET https://example.com  200 OK  142ms
✓ TLS 1.3 + HSTS enforced
✗ missing  content-security-policy
✗ server header exposes: nginx/1.18.0
✓ x-content-type-options: nosniff
✗ /sitemap.xml not found
✓ SPF record found
✗ no DMARC policy
WHOIS: GoDaddy · age 6.2 yrs · expires 2026-03
Host:  Cloudflare · AS13335 · United States

[ssl]      grade: A  · valid 284 days
[scores]   security: 58  seo: 85  perf: 73
[ai]       Posture is moderate. The most urgent
           gap is the missing CSP header.

Ready to inspect any link?

Free, instant, no account needed. Paste any URL and get your full report.