Tell Me When Down
How it worksWhat we checkPricing
Launch gradesBlogFree toolsCompareDocs
Log inGet started
free website security reportscan another site →
B

wakit.netlify.app

Grade B — 2 to fix, 1 minor.

0critical2to fix1minor

passive scan · the deep checks need you signed in · scanned 11h ago

This is a passive website security report for wakit.netlify.app, graded B (84/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.

We found 3 issues on this scan — each has a plain-English explanation and a copy-paste fix below.

Not your site? Get the same free report for yours →

Security headers03

No Content-Security-Policy

warning

There's no Content-Security-Policy header. A CSP is the single most effective defense against cross-site scripting (XSS): it tells the browser which sources of scripts, styles, and other content are allowed, so an injected <script> from a compromised dependency or a reflected input simply won't run.

Clickjacking not blocked

warning

Nothing stops your site from being embedded in an <iframe> on another domain. An attacker can overlay an invisible frame of your app on their page and trick a logged-in user into clicking buttons they can't see — a clickjacking attack.

No X-Content-Type-Options

info

Without `X-Content-Type-Options: nosniff`, browsers may guess ("sniff") the type of a response and, for example, run an uploaded file as JavaScript. It's a one-line header that closes a whole class of content-type confusion bugs.

Get the fixes — and go deeper

Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:

  • Exposed .env files (API keys & passwords)
  • Public .git folders (your whole codebase)
  • Leaked source maps of your original code
  • Open admin panels with no login
  • Debug pages left on (phpinfo, stack traces)
Fix these & go deeper

free for your first app · no card

Not wakit.netlify.app? Scan your own site free →

Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkLaunch gradesPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com