Non-invasiveNo exploitation, no login attempts, no brute-force attacks
Fully automated external security analysis in 24 hours. From domain to A-F Security Score with prioritized fix list.
Subdomains, open ports, running services, known CVEs, TLS configuration, security headers, HTTP responses, system uptime, SSL certificates
5 phases, 15 automated steps. Tools: nmap, Gossling SSL/TLS Scanner, nuclei, httpx, subfinder + CVE databases. Non-invasive, purely external scanning.
A-F Security Score, prioritized to-do list (Critical → Low), PDF reports, screenshots of all web services, concrete fix instructions per finding
CheckFix starts with subdomain enumeration via Certificate Transparency Logs, passive DNS databases, and permutation fuzzing. The tool finds not only your production systems but also forgotten development servers, old test environments, or shadow IT.
The discovered domains are resolved to IP addresses and enriched with geolocation and ASN data. This shows you which systems are running with which hosting provider and whether critical services are unexpectedly hosted in non-EU countries.
Example finding:“staging.example.com runs on outdated software and is publicly accessible”
CheckFix scans all 65,535 TCP ports per IP address and identifies running services: web servers, SSH, databases, mail servers, FTP, SMB, exposed admin panels. The detected software versions are automatically cross-referenced with the Vulners CVE database.
Additionally, CheckFix pulls historical data from Shodan – making visible even services that were recently closed but were exposed in the past.
Example finding:“Apache 2.4.29 on port 80 → CVE-2021-41773 (CVSS 9.8) → Remote code execution possible”
All HTTP/HTTPS services are analyzed in detail: Technology fingerprinting identifies CMS systems (WordPress, Drupal), JavaScript libraries, web frameworks, and CDN providers. Outdated installations, active debug modes, or publicly accessible admin panels are immediately detected.
CheckFix automatically creates screenshots of all websites – technical findings become visually traceable. Login panels, exposed dashboards, or misconfigurations are directly visible.
Example finding:“WordPress 5.8 detected → 12 known vulnerabilities, update to 6.4 recommended”
CheckFix checks all HTTP services for missing or misconfigured security headers: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy. Each missing header increases the risk of XSS attacks, clickjacking, or man-in-the-middle scenarios.
The Response Pattern Analysis correlates findings across all subdomains: If 15 different hosts use the same outdated jQuery or consistently run without HSTS, this indicates systematic infrastructure problems.
Example finding:“CSP completely missing → XSS attacks possible, HSTS not set → downgrade attacks risky”
CheckFix performs a comprehensive TLS/SSL analysis using our in-house testing system Gossling: Which protocol versions are active? Are insecure cipher suites such as RC4 or 3DES accepted? Are certificates valid and correctly configured? Do vulnerabilities like POODLE, BEAST, or Heartbleed exist?
The grading follows the methodology defined by Qualys SSL Labs (SSL Server Rating Guide). Gossling continuously runs comparison tests against SSL Labs to ensure consistent results. No intermediate grades (+/−) are assigned: each host receives the worst TLS grade across all tested endpoints, and the average of all host grades determines the company’s overall TLS score.
Gossling is also publicly available: At gossling.checkfix.io, anyone can check the TLS configuration of their own domain for free – in line with our open-source philosophy.
The System Uptime Detection analyzes TCP timestamps and identifies servers that have been running for months without a restart – an indicator of missing security updates and unpatched kernels.
Example finding:“TLS 1.0 still active + RC4 cipher allowed → Grade D → Downgrade attacks possible”
CheckFix automatically generates your security report and structures all findings into a prioritized to-do list:
CVSS 9.0+, F-Grade
Remote code execution, exposed databases, critical misconfigurations
CVSS 7.0-8.9, D/E-Grade
Outdated software with known exploits, missing HSTS headers
CVSS 3.0-6.9, B/C-Grade
Weak TLS configuration, missing security headers
CVSS 0.1-2.9, A-Grade
Best-practice optimizations, minor misconfigurations
High-level overview for management: Security Score, critical findings, industry benchmark
Prioritized checklist with direct fix instructions – ready for your ticketing system
Host-by-host analysis for security and IT teams: All details on ports, CVEs, TLS grades
Visual documentation of all web services – ideal for security reviews and audits
Each to-do contains concrete fix instructions: Which host is affected, what vulnerability exists, how to fix it. No interpreting raw data – simply work through the list from top to bottom.
CheckFix uses proven open-source tools and public databases:
| Reconnaissance: | subfinder, puredns, alterx, dnsx |
| Service Discovery: | nmap with Vulners integration, Shodan API |
| HTTP Analysis: | httpx, headless browser for screenshots |
| Vulnerability Scanning: | nuclei, testssl.sh |
| Intelligence: | IPInfo API, CVE databases |
All methods are reproducible, all tools and versions are documented – ideal for compliance audits.
|
✓
Non-invasiveNo exploitation, no login attempts, no brute-force attacks |
✓
Purely externalOnly publicly visible data, no agents on your servers |
✓
GDPR-compliantEU hosting, no personal data collected |
✓
Audit-readyReproducible methodology, documented tools & versions |
Difference from penetration testing: CheckFix identifies vulnerabilities automatically and non-invasively. A pentest actively and manually exploits them. CheckFix is ideal for regular security checks, pentests for more in-depth manual analyses after major changes.