Free tools

security.txt checker.

Check a site's /.well-known/security.txt against RFC 9116, or generate a valid one.

Generate a security.txt

The generator runs in your browser. Nothing you type here is sent anywhere.

One per line: an email address, an https:// page, or a phone number.

Add at least one contact and an expiry date, and the file appears here.

Serve it as text/plain at https://your-domain/.well-known/security.txt.

What it checks

Checks

  • That /.well-known/security.txt is served over HTTPS as text/plain, following up to three redirects.

  • The required fields: at least one Contact, and exactly one Expires in the future.

  • That Expires is less than a year away, and links are https:// URLs.

  • Whether a Canonical field names the address the file came from.

Doesn’t check

  • PGP signatures. A signed file is read, and the signature is noted but not verified.

  • Whether the contacts reach anyone.

  • The legacy /security.txt at the site's root.

Questions

What is security.txt?

A small text file, defined in RFC 9116, that tells security researchers how to report a vulnerability to you. It lives at /.well-known/security.txt.

How far away should Expires be?

Less than a year, so someone reviews the file regularly. Readers treat a file past its Expires date as stale.

Do I need to sign it?

No. A PGP signature is optional; it lets readers check the file was not changed by someone else.

Does the generator send my details anywhere?

No. The generator runs in your browser. Only the checker makes a request, to the site you enter.

Is what I enter stored?

No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.

Check a whole repository,
free.