• Security
Check if a website has a valid security.txt file and verify its format per RFC 9116.
Domain or URL only — e.g. example.com or https://example.com/page → checks example.com
• About this tool
Check if a website has a valid security.txt file at /.well-known/security.txt. Verify the format per RFC 9116 and see contact, policy, and expiry fields.
• FAQ
security.txt is a proposed standard (RFC 9116) that lets websites define a security contact point for responsible vulnerability disclosure.
At /.well-known/security.txt. The old location /security.txt is a fallback.
Only Contact is required. Expires is strongly recommended. Optional fields include Policy, Encryption, Acknowledgments, and Preferred-Languages.
It is not legally required but is considered a security best practice and is required for some compliance frameworks and bug bounty programs.
• Related
HTTP Security Headers Checker
Audit the HTTP security headers of any website. Score CSP, HSTS, X-Frame-Options, and more.
Robots.txt Analyzer
Fetch and parse any website's robots.txt file. See allowed/disallowed paths, crawl delays, and sitemap references.
SSL Certificate Checker
Inspect the SSL/TLS certificate for any domain. Check validity, expiry, issuer, and certificate chain.
• automated security
PandaONE runs autonomous agents against your app, validates findings with proof, and opens fixes as pull requests.
Get started