Is your website secure?
Run a free security scan.
Enter your domain for a free PDF report of your site’s flaws and risks. Want them fixed? We’re developers.
Scan your website
scanning…A passive security check, then a downloadable PDF report of the flaws and risks we find.
Is scanning my site safe?
Yes. The scan is passive and read-only — it reads only what your server already shows any browser (HTTP headers, TLS certificate, public HTML, DNS). We never log in, never attack, never change anything, and it’s invisible to your visitors.
Don't trust us — verify it
Open DevTools → Network and scan. The instant check runs entirely in your browser — the only requests it fires are DNS-over-HTTPS lookups to public resolvers (dns.google / cloudflare-dns.com). Your address never reaches a Kalenfy server until you choose to send it for the full PDF.
Your report is ready
Enter your email and we'll send you the full PDF report.
- Your A–F grade + 0–100 score
- Every flaw with CVSS, CWE & OWASP class
- Plain-English risk for each one
- A P0–P3 fix plan with timeframes
Free, no paywall · one email, no list, no spam · GDPR — how we handle it.
Why an email?
Your PDF is built right here in your browser. The email is only how we deliver it — and how we follow up with the deeper full-surface findings (TLS, security headers, exposed files) that the instant scan can't read. One email, no list, no drip.
Sent.
What Kalenfy checks
We review the public signals that matter most to a site's real security — without touching anything private.
Kalenfy does not analyse private areas, internal panels, databases, server code or business logic. That requires a full technical audit.
How a finding reads
Every risk is explained with context: what it is, its impact, the real priority it deserves and how much it costs to fix.
The report doesn't replace a full audit, but it does catch many visible problems that usually go unnoticed.
How it works
Enter your domain
We only need your site's public URL. No access, no installs.
We analyse visible signals
We review public configuration and common risks without touching private areas.
You get an actionable report
We show what to fix first, why it matters, and what to do next.
Finding the problem is only half of it. We can fix it too.
Use the report yourself or hand us the work. Each service is a fixed scope, no surprises. We're developers.
Fix Pack
For sites with basic configuration problems.
- ·Basic headers
- ·HTTPS / redirects
- ·SPF, DKIM & initial DMARC
- ·Exposed-files review
- ·Hardening recommendations
WordPress Secure
POPULARFor WordPress, WooCommerce or corporate blogs.
- ·Safe updates
- ·Plugin review
- ·Backups
- ·Login hardening
- ·Users & permissions
- ·Firewall / security plugin
- ·Visible-malware review
Emergency Cleanup
For infected sites, odd redirects, blacklisting or malware.
- ·Diagnosis
- ·Cleanup
- ·Restore
- ·User review
- ·Search Console
- ·Post-incident advice
Care Plan
Monthly security maintenance.
- ·Monitoring
- ·Backups
- ·Updates
- ·Monthly report
- ·Small fixes
- ·Technical support
Use cases
Small businesses
Your site works, but nobody checks whether it's properly protected.
E-commerce
Cut visible risks before campaigns, traffic spikes or external audits.
Agencies
Offer web security to your clients without building an in-house team.
Technical teams
Get a fast report to prioritise hardening tasks.
Security without noise, fear or aggressive tactics.
Kalenfy runs passive checks on public information. It does not try to access private systems, exploit vulnerabilities, force credentials or publish third-party results.
When we find a risk, we explain it with context: what it means, what impact it can have and what real priority it should get.
- —No attacks
- —No exploiting flaws
- —No scanning private areas
- —We never sell data
- —No scare tactics
- —We never inflate severities to sell
Guide prices
Start free with the scan. If you want it fixed, every service has a clear starting point.
What people usually ask
Does Kalenfy hack my site?+
No. The analysis is passive and based on public information and visible configuration.
Do I need to install anything?+
Not for the initial scan. You just enter your domain.
Does the report replace a full audit?+
No. It's a public, preliminary review. A full audit needs technical access, context and deeper testing.
Can you fix the problems?+
Yes. We're developers — use the report yourself or ask us to fix what we find.
Does it work with WordPress?+
Yes. Kalenfy is especially useful for WordPress, WooCommerce, corporate sites and small shops.
Can I use it with my agency's clients?+
Yes. A white-label model for agencies is possible.
Start by knowing what's exposed.
Enter your domain and get a first clear read of your site's visible risks. No attacks, no fear, no commitment.
Scan my website free →Passive scan · public information only · no commitment
Questions? Talk to us
Want a hand fixing what the scan finds, or have a question? Send a message — we're developers, and we actually reply.
info@kalenfy.com