No email, no sign-up. This is exactly what a free Solvbeat scan gives you — every finding, why it matters, and how to fix it. The site below is made up, but the checks are the real ones.
3 critical, 5 medium, 211 checks passed. A solid site with a few real gaps worth closing this week.
Your site serves jQuery 1.12.4, which has publicly documented cross-site scripting vulnerabilities (CVE-2020-11022, CVE-2020-11023). Automated attack tools fingerprint versions like this and try known exploits without a human ever being involved.
A .map file is publicly reachable next to your production JavaScript. It reveals your unminified source code and internal file paths — a free map of your app for anyone probing it.
*.map at your web server / CDN edge.Without a DMARC policy, an attacker can send email that appears to come from your domain — the classic setup for invoice fraud and phishing your own clients. For a law firm, that's a direct client-trust risk.
p=none to monitor, then move to p=quarantine once your legitimate senders pass.Two browser-level protections are absent: Content-Security-Policy and Strict-Transport-Security. They defend against script injection and protocol-downgrade attacks.
A session cookie is sent without the Secure attribute, meaning it could be transmitted over an unencrypted connection and intercepted.
Secure, HttpOnly and SameSite on all session cookies.Valid certificate, strong protocol versions, no weak ciphers, and comfortable time before expiry. Nothing to do here — this is what good looks like.
No card, no sign-up to see your findings. Just your domain.
Run my free scan →