ChatSniff

Security Sniff

Security Sniff

Spot risky exposures and weak configurations before they become a problem.

ChatSniff doesn't attack your website.

It looks for things you probably shouldn't be exposing — only what any visitor can see. Deeper checks require proof that you own the site.

No sign-upFreeActionable results

Real example · faceabot.com

Category score 90/100

Sniffed 2026-10-07 · See the full report

2Smells bad
4Needs attention
1Opportunities
14Smells good

We check the security hygiene that matters

Passive checks for everyone; exposed-file checks for verified owners.

HTTPS & redirects

Secure by default, HTTP redirected permanently.

Security headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.

Mixed content

Insecure HTTP resources on secure pages.

Visible versions

Server, framework and CMS versions that help attackers.

Cookies & forms

Secure, HttpOnly, SameSite flags; forms posting over HTTP.

Exposed files (verified owners)

.env, .git, backups, phpinfo — checked only with your proof of ownership.

A more secure website builds trust

Security headers cost nothing and block whole families of attacks. ChatSniff writes the exact lines for your server: Cloudflare, Nginx, Apache, Netlify or Vercel.

From sniff to a safer website

1

Enter your website

Passive check, nothing intrusive.

2

We analyse

Headers, cookies, versions, mixed content.

3

See what's risky

High, medium and low priorities.

4

Fix and stay safe

Copy the ready-made configuration.

Ready to improve your website?

Check your website security today

Find risky exposures. Fix them. Build a safer website.