Device Security Score

Device Security Score

15-question device-hygiene score for your laptop or phone.

Privacy: answers stay in your browser. We do not record your responses.
A lost device without encryption = a data breach. Enable it now.
Out-of-date OS is the #1 malware infection vector for consumer devices.
Shoulder-surfing and casual access attacks happen. Lock fast.
No swipe-to-unlock. Even a 6-digit PIN is meaningful friction.
Remote-wipe a lost device in seconds. Enable this now if you haven't.
Side-loaded apps are the #1 Android malware vector.
Microphone, location, contacts — most apps have permissions they don't need.
Windows Defender is on by default and is fine for most people. Don't disable it.
Every installed app is attack surface. Prune quarterly.
Both ship with a firewall. Turn it on.
Old Bluetooth stacks have exploitable vulns. Toggle off when not paired.
Phone left on the coffee shop table for 10 min is free access.
Regular reboots clear a lot of memory-resident malware and apply pending OS updates.
If ransomware hits, your backup is your only path back.
Serial number, purchase receipt. Critical for lost/stolen claims and insurance.
Score
Answer the questions above to see your score.

Home WiFi Security Checker

Home WiFi Security Checker

10 questions about your home router and WiFi setup — find the 3 things to fix.

Privacy: answers stay in your browser. We do not record your responses.
WEP is broken; open WiFi is exposed. Switch to WPA2 at minimum, WPA3 if your router supports it.
Default passwords are indexed in public databases. Change it today.
Log into the admin page, look for "firmware" or "update." Many consumer routers haven't been updated in years.
WPS has known attacks. Disable it if your devices don't require it.
Short WPA2 passwords can be cracked offline in days. 14+ mixed characters pushes that to decades.
Isolate smart TVs, doorbells, and visitor devices from your laptops on a guest VLAN.
Attackers scan the internet for exposed router admin pages. Turn it off unless you need it.
Most consumer routers stop receiving security updates around year 5. If you're past that, replace it.
Most router admin pages show every device — check for unfamiliar ones.
Stops connections to known-malicious domains at the DNS layer.
Score
Answer the questions above to see your score.

Browser Security Checker

Browser Security Checker

10 questions — is your browser protecting you like it should?

Privacy: answers stay in your browser. We do not record your responses.
Chrome, Firefox, Edge, Safari all auto-update. Open about: and verify.
Extensions can read everything you type. Prune to what you actually use.
Beyond ads: blocks known malicious domains and trackers.
Firefox and Chrome both support "HTTPS-only" that blocks plain HTTP pages.
Chrome: Settings → Privacy → Safe Browsing. Firefox: equivalent under Privacy.
Profile isolation contains compromise and reduces cross-site tracking.
Firefox and Safari block by default. Chrome has "Block third-party cookies" option.
Browser autofill leaks credentials to malicious scripts. Use 1Password / Bitwarden instead.
That dusty old Edge / Internet Explorer you never use is still a target.
Or use "clear on exit" for third-party sites.
Score
Answer the questions above to see your score.

Privacy Score Checker

Privacy Score Checker

12 questions — privacy posture across browser, OS, and accounts.

Privacy: answers stay in your browser. We do not record your responses.
Chrome without extensions sends a lot of telemetry. Firefox or Brave block most trackers automatically.
uBlock Origin is free, open-source, and blocks most ad and tracking networks.
Apps collect location, contacts, microphone access. Settings → Privacy → review each.
Ad-supported email scans content for ads. Either switch or disable personalization.
Dedicated password managers isolate credentials from your browser profile.
Services like DeleteMe, Privacy Bee, or manual opt-outs via Intelius/Spokeo help.
Hide My Email / Firefox Relay / SimpleLogin prevent leak spread.
Most apps don't need "always" location. Switch to "while using" or off.
iOS: Settings → Privacy → Tracking → off. Android: Settings → Privacy → Ads → delete advertising ID.
Your ISP sees every DNS lookup by default. Switch to 1.1.1.1 or NextDNS in 2 minutes.
Public profiles are the primary research source for scammers and stalkers.
Or use our Password Leak Checker and Username Leak Checker — free, no signup.
Score
Answer the questions above to see your score.

SMB Cyber Risk Score

SMB Cyber Risk Score

20 questions — get an actionable risk score and the top things to fix first.

Privacy: answers stay in your browser. We do not record your responses.
Multi-factor authentication is the single highest-impact control. Turn it on everywhere administrative.
Modern EDR (Windows Defender for Business, SentinelOne, CrowdStrike) is table stakes.
A backup you haven't tested to restore is a backup you don't have.
Deploy 1Password / Bitwarden / Dashlane company-wide. Password policies alone don't work.
A lost laptop becomes a breach without disk encryption. Both Windows and macOS ship with it free.
Even basic free training (KnowBe4 free tier, Hoxhunt) reduces click-through on real phishing.
Most ransomware exploits known vulnerabilities patched months ago. Close the window.
When a breach happens you don't want to be googling "what to do." Write it now.
Dormant accounts are a favourite attacker pivot. Automate offboarding checklists.
Most business routers support VLAN or guest-network separation. Turn it on.
SSO means one place to disable access for departed employees, and one place to enforce MFA.
Insurance is a financial safety net, not a control. Read the exclusions before an incident.
Least-privilege access on anything sensitive: HR, finance, customer PII.
Your weakest vendor is your effective security floor. Ask for SOC 2 + DPA at minimum.
BEC is the #1 financial cyber loss. Require out-of-band verification for any money movement.
Without logs you can't investigate anything. Most platforms log for free — just enable it.
Walk your Google Drive / OneDrive — would a new hire see things they shouldn't?
Free tools like SSL Labs, SafeCadence's Security Headers Checker cover the basics.
Rotate privileged creds + review access logs once a month; takes 20 minutes.
If security is "everyone's job" it's no-one's job. Name one person accountable.
Score
Answer the questions above to see your score.

Reverse DNS Lookup

Reverse DNS (PTR) lookup

MD5 Hash Checker

MD5 hash

Legacy tool. MD5 is broken for cryptographic purposes — use for file-integrity checks only.
MD5 (hex)

Robots.txt Checker

Inspect robots.txt

HTTP Header Viewer

HTTP headers