Security tool
security.txt Checker
Check whether /.well-known/security.txt is present and usable.
How it works
security.txt (RFC 9116) tells researchers how to report vulnerabilities responsibly. We request /.well-known/security.txt on your public origin and look for Contact plus helpful fields like Expires and Policy. Missing files score poorly; present files with a clear contact score better. Shipping security.txt will not patch XSS, but it signals operational maturity - useful for enterprise buyers and for diverting reports away from social media. Keep the contact monitored; an ignored inbox is worse than no file. We do not validate PGP keys, crawl linked policies, or check every historical path (only the well-known location on this pass). After you publish the file, re-run this tool, then scan the live app with AtRisk so the product behind the trust signal is actually hardening. Teaser depth only - not a pentest or bug-bounty program setup guide, though it is a good first step toward one. Keep Expires updated so researchers know the file is maintained, and link a short policy page when you can.
This is a free teaser check - not a penetration test, vulnerability assessment, or compliance audit. AtRisk full scans go deeper across more detectors and unlock fix prompts on Starter.