Skip to the scanner
Kalenfy logo Kalenfy

Is your website secure?
Run a free security scan.

Enter your domain for a free PDF report of your site’s flaws and risks. Want them fixed? We’re developers.

Scan your website

A passive security check, then a downloadable PDF report of the flaws and risks we find.

Is scanning my site safe?

Yes. The scan is passive and read-only — it reads only what your server already shows any browser (HTTP headers, TLS certificate, public HTML, DNS). We never log in, never attack, never change anything, and it’s invisible to your visitors.

Don't trust us — verify it

Open DevTools → Network and scan. The instant check runs entirely in your browser — the only requests it fires are DNS-over-HTTPS lookups to public resolvers (dns.google / cloudflare-dns.com). Your address never reaches a Kalenfy server until you choose to send it for the full PDF.

Passive, read-only scan
No exploitation, no attacks
Readable for business and tech alike
Prioritised by real impact
Scan scope

What Kalenfy checks

We review the public signals that matter most to a site's real security — without touching anything private.

DNS & domain01

SPF, DKIM, DMARC, CAA, DNSSEC and public configuration signals.

HTTPS & TLS02

Certificates, redirects, insecure protocol versions and basic setup.

Security headers03

HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy and more.

Cookies & sessions04

Secure, HttpOnly and SameSite flags and other visible settings.

Exposed files05

Careful detection of visible sensitive paths like .env, .git, backups or config files.

Visible technologies06

CMS, exposed versions, frameworks, libraries and signs of obsolescence.

i

Kalenfy does not analyse private areas, internal panels, databases, server code or business logic. That requires a full technical audit.

Real example

How a finding reads

Every risk is explained with context: what it is, its impact, the real priority it deserves and how much it costs to fix.

FINDING-03

DMARC not configured

Medium riskemail-security
Impact

Your domain can be used in spoofing campaigns if SPF/DKIM aren't properly aligned.

Recommendation

Publish an initial DMARC policy in monitoring mode and review alignment with your real mail providers.

Evidence

_dmarc.yourdomain.com
→ NXDOMAIN

DifficultyLow · DNS
Estimated time~30 min
ReversibleYes
Checks summary
strict-transport-securitymissingHigh
content-security-policymissingHigh
x-frame-optionsSAMEORIGINOK
.git/HEAD200 OKCritical

The report doesn't replace a full audit, but it does catch many visible problems that usually go unnoticed.

Process

How it works

01

Enter your domain

We only need your site's public URL. No access, no installs.

02

We analyse visible signals

We review public configuration and common risks without touching private areas.

03

You get an actionable report

We show what to fix first, why it matters, and what to do next.

Try it with my domain →
Fixing services

Finding the problem is only half of it. We can fix it too.

Use the report yourself or hand us the work. Each service is a fixed scope, no surprises. We're developers.

Fix Pack

For sites with basic configuration problems.

  • ·Basic headers
  • ·HTTPS / redirects
  • ·SPF, DKIM & initial DMARC
  • ·Exposed-files review
  • ·Hardening recommendations
From
€249
Fix my website

WordPress Secure

POPULAR

For WordPress, WooCommerce or corporate blogs.

  • ·Safe updates
  • ·Plugin review
  • ·Backups
  • ·Login hardening
  • ·Users & permissions
  • ·Firewall / security plugin
  • ·Visible-malware review

Emergency Cleanup

For infected sites, odd redirects, blacklisting or malware.

  • ·Diagnosis
  • ·Cleanup
  • ·Restore
  • ·User review
  • ·Search Console
  • ·Post-incident advice

Care Plan

Monthly security maintenance.

  • ·Monitoring
  • ·Backups
  • ·Updates
  • ·Monthly report
  • ·Small fixes
  • ·Technical support
From
€99/mo
See maintenance
Who it's for

Use cases

Small businesses

Your site works, but nobody checks whether it's properly protected.

E-commerce

Cut visible risks before campaigns, traffic spikes or external audits.

Agencies

Offer web security to your clients without building an in-house team.

Technical teams

Get a fast report to prioritise hardening tasks.

Ethics & limits

Security without noise, fear or aggressive tactics.

Kalenfy runs passive checks on public information. It does not try to access private systems, exploit vulnerabilities, force credentials or publish third-party results.

When we find a risk, we explain it with context: what it means, what impact it can have and what real priority it should get.

  • No attacks
  • No exploiting flaws
  • No scanning private areas
  • We never sell data
  • No scare tactics
  • We never inflate severities to sell
Plans

Guide prices

Start free with the scan. If you want it fixed, every service has a clear starting point.

Free

€0
  • ·Public scan
  • ·Risk summary
  • ·Basic recommendations
  • ·Downloadable PDF
Scan free

Fix

From €249
  • ·Basic configuration fixes
  • ·Headers
  • ·HTTPS
  • ·Email security
  • ·Public exposure review
Request a fix

Secure

From €499
  • ·Advanced hardening
  • ·WordPress / CMS
  • ·Backup
  • ·Plugins & users
  • ·Security configuration
Request a review

Care

From €99/mo
  • ·Monitoring
  • ·Backups
  • ·Updates
  • ·Monthly report
  • ·Ongoing support
Start care plan
FAQ

What people usually ask

Does Kalenfy hack my site?+

No. The analysis is passive and based on public information and visible configuration.

Do I need to install anything?+

Not for the initial scan. You just enter your domain.

Does the report replace a full audit?+

No. It's a public, preliminary review. A full audit needs technical access, context and deeper testing.

Can you fix the problems?+

Yes. We're developers — use the report yourself or ask us to fix what we find.

Does it work with WordPress?+

Yes. Kalenfy is especially useful for WordPress, WooCommerce, corporate sites and small shops.

Can I use it with my agency's clients?+

Yes. A white-label model for agencies is possible.

Start by knowing what's exposed.

Enter your domain and get a first clear read of your site's visible risks. No attacks, no fear, no commitment.

Scan my website free →

Passive scan · public information only · no commitment

Contact

Questions? Talk to us

Want a hand fixing what the scan finds, or have a question? Send a message — we're developers, and we actually reply.

info@kalenfy.com