Skip to content

SSL / TLS check:Will your visitors see a browser security warning?

See whether your certificate is valid and when it expires, which TLS versions your server accepts, and whether every page and file loads over HTTPS.

  • Free, no account
  • Results in under a minute
  • Any public HTTPS site
Example result

example-shop.hr

WordPress 6.8

Sample shop · homepage · mobile Chrome · the same check you get for your own site

Run it on your site
Security

1 passed · 1 failed · 0 warnings. Biggest issue: The site is served over HTTP, not HTTPS.

What we found

1 failed0 warnings1 to note1 passed
Show 1 passed checks

Fix these first

From the example above. Check your own site to get the fixes that apply to it.

  1. Problem: The site is served over HTTP, not HTTPS

    Browsers label HTTP pages "Not secure" and Google ranks HTTPS pages higher.

    How to fix it: Get a certificate (Let's Encrypt is free) and enable HTTPS on your host.

What this tool checks

Eight checks on your certificate, protocols and HTTPS setup, each with the fix.

  • HTTPS connection

    Checks the site is served over HTTPS, so browsers don't label it "Not secure" and visits stay private.

  • HTTP to HTTPS redirect

    Checks that old http:// links and typed addresses land on the encrypted https:// page.

  • HSTS header

    Checks the header that keeps return visits on HTTPS, so they never start on interceptable plain HTTP.

  • HSTS preload readiness

    Checks your HSTS header qualifies for the browsers' built-in HTTPS-only list.

  • Minimum TLS version

    Checks the server refuses old TLS 1.0 and 1.1, which attackers can use to weaken a connection.

  • Certificate expiry

    Shows how many days your TLS certificate has left, before browsers show a full-page warning.

  • Certificate chain

    Checks browsers can verify who issued your certificate, so visitors don't see a privacy warning.

  • Mixed content

    Finds files loaded over http:// on an HTTPS page, which browsers block or mark as not secure.

Show 4 more checks
  • Minimum TLS version

    Checks the server refuses old TLS 1.0 and 1.1, which attackers can use to weaken a connection.

  • Certificate expiry

    Shows how many days your TLS certificate has left, before browsers show a full-page warning.

  • Certificate chain

    Checks browsers can verify who issued your certificate, so visitors don't see a privacy warning.

  • Mixed content

    Finds files loaded over http:// on an HTTPS page, which browsers block or mark as not secure.

How it works

  1. Check HTTPS

    We check that the site is served over HTTPS and that http:// addresses redirect to it, and whether HSTS is set.

  2. Run a TLS handshake

    A TLS handshake against the host checks the certificate chain, the days left before expiry, and whether TLS 1.0 or 1.1 are still accepted.

  3. Look for mixed content

    The page is checked for any image, script or other resource that still loads over plain HTTP.

This is a practical check of certificate, chain, expiry and protocol versions, not a full cipher-suite audit like SSL Labs.

Questions

Is this really free?

Yes. getReport is funded by donations, not plans. This tool runs the full report and shows you the part it is about; the complete report with all seven modules is one click away, also free.

What does the TLS check test?

We run a TLS handshake against the host and check the chain, expiry, and whether TLS 1.0 or 1.1 are still accepted. It is a practical check, not a full cipher-suite audit like SSL Labs.

Will you alert me before the certificate expires?

Monitoring with TLS-expiry alerts (14 days ahead) is a funded unlock. See the funding page for the current threshold.

Do you store my results?

The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag; nothing about your visitors is collected.

Why does TLS matter?

An expired certificate or a broken chain shows every visitor a full-page warning and stops them cold. Old TLS versions fail in modern browsers and in compliance scans. HTTPS has been a ranking signal since 2014, and Chrome marks plain HTTP pages as not secure. With free certificates from Let's Encrypt there is no reason left to serve HTTP.

All 41 tools →

Free, funded by the people who use it

€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.

Chip in