Tell Me When Down
How it worksWhat we checkPricing
Security reportsBlogFree toolsCompareDocs
Log inGet started
← all reportsscan another site →
B

share.google

Grade B — 3 to fix, 2 minor.

0critical3to fix2minor

passive scan · the deep checks need you signed in · scanned 27d ago

This is a passive website security report for share.google, graded B (75/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.

We found 5 issues on this scan — each has a plain-English explanation and a copy-paste fix below.

Not your site? Get the same free report for yours →

Security headers03

No HSTS header

warning

Your site is served over HTTPS but doesn't send a Strict-Transport-Security header. Without it, the first visit (or a link typed as http://) can be intercepted and downgraded to plain HTTP before the redirect happens — a foothold for man-in-the-middle attacks on public Wi-Fi.

Clickjacking not blocked

warning

Nothing stops your site from being embedded in an <iframe> on another domain. An attacker can overlay an invisible frame of your app on their page and trick a logged-in user into clicking buttons they can't see — a clickjacking attack.

Weak Content-Security-Policy

info

You have a Content-Security-Policy, which is great — but it contains a wildcard source or allows 'unsafe-inline'/'unsafe-eval' in script-src. Those let injected scripts execute, which is most of what a CSP is meant to stop.

Certificate & encryption01

HTTP isn't redirected to HTTPS

warning

Visiting http://share.google (no "s") serves the site over an unencrypted connection instead of redirecting to HTTPS. Anyone typing the bare domain, or following an old http:// link, gets an unencrypted page where their traffic can be read or modified in transit.

DNS security01

DNSSEC is not enabled

info

share.google is not protected by DNSSEC. DNSSEC signs your DNS records so resolvers can detect a forged answer — without it, an attacker who can poison DNS could point your domain at their own server without touching anything you control.

Get the fixes — and go deeper

Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:

  • Exposed .env files (API keys & passwords)
  • Public .git folders (your whole codebase)
  • Leaked source maps of your original code
  • Open admin panels with no login
  • Debug pages left on (phpinfo, stack traces)
Fix these & go deeper

free for your first app · no card

Not share.google? Scan your own site free →

Or browse every site we've graded.

Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkSecurity reportsPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com