security.txt checker.
Check a site's /.well-known/security.txt against RFC 9116, or generate a valid one.
Generate a security.txt
The generator runs in your browser. Nothing you type here is sent anywhere.
Add at least one contact and an expiry date, and the file appears here.
Serve it as text/plain at https://your-domain/.well-known/security.txt.
What it checks
Checks
That /.well-known/security.txt is served over HTTPS as text/plain, following up to three redirects.
The required fields: at least one Contact, and exactly one Expires in the future.
That Expires is less than a year away, and links are https:// URLs.
Whether a Canonical field names the address the file came from.
Doesn’t check
PGP signatures. A signed file is read, and the signature is noted but not verified.
Whether the contacts reach anyone.
The legacy /security.txt at the site's root.
Questions
What is security.txt?
A small text file, defined in RFC 9116, that tells security researchers how to report a vulnerability to you. It lives at /.well-known/security.txt.
How far away should Expires be?
Less than a year, so someone reviews the file regularly. Readers treat a file past its Expires date as stale.
Do I need to sign it?
No. A PGP signature is optional; it lets readers check the file was not changed by someone else.
Does the generator send my details anywhere?
No. The generator runs in your browser. Only the checker makes a request, to the site you enter.
Is what I enter stored?
No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.