TLS certificate expires in 7 days
warningThe HTTPS certificate for facebook.com expires on Wed, 29 Jul 2026 23:59:59 GMT. If it isn't renewed in time, every visitor will hit a browser security warning.
Grade B — 1 to fix, 3 minor.
passive scan · the deep checks need you signed in · scanned 1d ago
This is a passive website security report for facebook.com, graded B (87/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.
We found 4 issues on this scan — each has a plain-English explanation and a copy-paste fix below.
Not your site? Get the same free report for yours →
The HTTPS certificate for facebook.com expires on Wed, 29 Jul 2026 23:59:59 GMT. If it isn't renewed in time, every visitor will hit a browser security warning.
You have a Content-Security-Policy, which is great — but it contains a wildcard source or allows 'unsafe-inline'/'unsafe-eval' in script-src. Those let injected scripts execute, which is most of what a CSP is meant to stop.
facebook.com is not protected by DNSSEC. DNSSEC signs your DNS records so resolvers can detect a forged answer — without it, an attacker who can poison DNS could point your domain at their own server without touching anything you control.
These cookies don't set SameSite: fr, sb. SameSite limits when the browser attaches a cookie to cross-site requests, which is a key defence against CSRF (a malicious site making authenticated requests as your user).
Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:
free for your first app · no card
Not facebook.com? Scan your own site free →