SSL & Security

Advanced SSL/TLS Security Scanner

Vulnerability Scan

Run a security scan

Enter a domain name and port to perform comprehensive SSL/TLS security analysis, detect vulnerabilities, and get detailed security assessments.

Tool features

Comprehensive SSL/TLS security scanning with vulnerability detection, security scoring, and professional reporting
4 checks

Vulnerability detection

Detect Heartbleed, POODLE, BEAST, CRIME, and other SSL/TLS vulnerabilities.

Security scoring

Get a comprehensive security score and risk assessment for the endpoint.

Professional reporting

Detailed reports with prioritised recommendations and best practices.

Certificate analysis

Validate certificates, check chain completeness, and analyze TLS versions.

What is an SSL/TLS security scan & how it works

Vulnerabilities, protocols, and scoring in one pass

An SSL/TLS security scan goes beyond checking that a certificate is valid — it probes the whole HTTPS endpoint for weaknesses. It tests which protocol versions and cipher suites are enabled, checks the certificate chain, and looks for the specific misconfigurations that well-known attacks (Heartbleed, POODLE, BEAST, CRIME) exploit.

This scanner runs those checks against the host and port you provide and rolls the findings up into a single security score with prioritised recommendations. It is the fastest way to see, at a glance, whether a server would pass a security audit or expose users to downgrade, interception, or data-leak vulnerabilities.

Heartbleed
A memory-disclosure flaw (CVE-2014-0160) in old OpenSSL versions that could leak private keys and session data.
POODLE / BEAST
Attacks that exploit SSL 3.0 and TLS 1.0 weaknesses. Disabling those protocols is the fix.
Security score
An overall grade summarising protocol strength, cipher quality, certificate health, and known vulnerabilities.

How to use this tool

Run a full SSL/TLS security scan in four steps
1
Enter a domain and port
Type the hostname and port (443 for HTTPS) and pick a scan depth.
2
Choose a scan type
Basic for a quick look, comprehensive for full coverage, or vulnerability-focused.
3
Run the scan
We probe protocols, ciphers, the certificate chain, and known CVEs against the endpoint.
4
Act on the report
Fix the highest-severity findings first — disable weak protocols, patch OpenSSL, complete the chain.

Related tools

Keep debugging with tools from the same suite
4 tools
SSL Checker
Comprehensive SSL certificate analysis including validity, expiration, chain verification, TLS versions, and security assessment
SSL Expiration Checker
Check SSL certificate expiration dates and get alerts before certificates expire
TLS Checker
Check supported TLS versions and cipher suites on a server for security compliance
Secure Header Checker
Check security headers like CSP, HSTS, X-Frame-Options, and more with security scoring

Frequently asked questions

Common questions about SSL/TLS security scanning
5 Q&A

It tests for well-known SSL/TLS issues including Heartbleed, POODLE, BEAST, and CRIME, plus weak protocol versions, insecure cipher suites, and certificate-chain problems.

The score aggregates protocol strength (TLS 1.2/1.3 vs deprecated versions), cipher quality, certificate validity and chain completeness, and the presence of any known vulnerabilities.

Basic runs the essential checks quickly, comprehensive covers protocols, ciphers, and certificates in full, and vulnerability-focused prioritises detection of known CVEs and downgrade risks.

Fix the highest-severity findings first: disable SSL 3.0/TLS 1.0/1.1, remove weak ciphers, patch outdated OpenSSL, and install any missing intermediate certificates.

Yes. The scanner performs standard read-only handshakes and probes; it does not exploit vulnerabilities or send malicious payloads.