Security

security.txt Checker

Check if a website has a valid security.txt file and verify its format per RFC 9116.

Domain or URL only — e.g. example.com or https://example.com/page → checks example.com

About this tool

What is security.txt Checker?

Check if a website has a valid security.txt file at /.well-known/security.txt. Verify the format per RFC 9116 and see contact, policy, and expiry fields.

security.txt checkersecurity.txt validatorrfc 9116vulnerability disclosureresponsible disclosure policysecurity contact

FAQ

Frequently asked questions

What is security.txt?

security.txt is a proposed standard (RFC 9116) that lets websites define a security contact point for responsible vulnerability disclosure.

Where should security.txt be placed?

At /.well-known/security.txt. The old location /security.txt is a fallback.

What fields are required?

Only Contact is required. Expires is strongly recommended. Optional fields include Policy, Encryption, Acknowledgments, and Preferred-Languages.

Do I need security.txt?

It is not legally required but is considered a security best practice and is required for some compliance frameworks and bug bounty programs.

Related

automated security

Need continuous coverage?

PandaONE runs autonomous agents against your app, validates findings with proof, and opens fixes as pull requests.

Get started