Tell Me When Down
How it worksWhat we checkPricing
Security reportsBlogFree toolsCompareDocs
Log inGet started
← all reportsscan another site →
C

acmedemo.dev

Grade C — 5 to fix, 2 minor.

0critical5to fix2minor

passive scan · the deep checks need you signed in · scanned 61d ago

This is a passive website security report for acmedemo.dev, graded C (61/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.

We found 7 issues on this scan — each has a plain-English explanation and a copy-paste fix below.

Not your site? Get the same free report for yours →

Email spoofing protection02

No DMARC record — your domain can be spoofed

warning

acmedemo.dev publishes no DMARC record. Without it, anyone can send email that appears to come from your domain, and inboxes have no signal to distrust it — a favourite trick for invoice fraud and credential phishing.

No SPF record

warning

The domain publishes no SPF record listing which mail servers may send as your domain, so spam filters can't tell your real mail from a forgery.

Certificate & encryption01

TLS certificate expires in 9 days

warning

The HTTPS certificate expires soon. If it isn't renewed in time, every visitor will hit a full-page browser security warning.

Exposed attack surface01

3 sensitive subdomains publicly discoverable

warning

Public Certificate Transparency logs reveal internal-looking hostnames under this domain: staging, dev, and admin. Attackers find these the same way we did — from public logs, no scanning required.

Security headers01

No HSTS header

warning

Served over HTTPS but without a Strict-Transport-Security header, so the very first visit can be downgraded to plain HTTP before the redirect happens.

Cookie security01

Cookies readable by JavaScript

info

The session cookie is set without HttpOnly, so any script on the page — including one injected through an XSS bug — can read it.

DNS security01

DNSSEC is not enabled

info

The domain is not protected by DNSSEC, so a resolver can't detect a forged DNS answer pointing your domain elsewhere.

Get the fixes — and go deeper

Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:

  • Exposed .env files (API keys & passwords)
  • Public .git folders (your whole codebase)
  • Leaked source maps of your original code
  • Open admin panels with no login
  • Debug pages left on (phpinfo, stack traces)
Fix these & go deeper

free for your first app · no card

Not acmedemo.dev? Scan your own site free →

Or browse every site we've graded.

Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkSecurity reportsPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com