Hacker News new | past | comments | ask | show | jobs | submit login

What other/similar analyzers are out there?

HTTPSecurityReport - https://httpsecurityreport.com - Disclaimer: I'm the creator.

Site Scan from MS - https://dev.windows.com/en-us/microsoft-edge/tools/staticsca...

Subresource Integrity scanner - https://sritest.io/

Maybe you can add HTTP2/SPDY detection too. BTW your HSTS test does not verify if the format/syntax is correct.


These are all good but I would include the following:

Qualys SSL Server Test - The first site I use.

testssl.sh - for behind the fireware testing

https://tls.imirhil.fr/ - this one is nice because it shows the ciphers used/avail broken down by TLS version. I have not seen any other site do this.

Thanks for these! I like that yours covered a lot more than the one OP posted.

Thanks, glad to hear it!

HTTPSecurityReport is great! Thank you!

For SSL from Qualys, Inc https://www.ssllabs.com/ssltest/

Last I checked, Qualys only scanned port 443. I like testssl.sh - you can point it at arbitrary ports:

https://testssl.sh/ https://github.com/drwetter/testssl.sh

testssl.sh is also great for testing internal servers which aren't internet accessible.

https://ssl-tools.net/ is nice because it will continously retest and email you if there's a problem. Also does mail servers

https://mxtoolbox.com/ can give some decent information when setting up a mail server.

There's also https://starttls.info/ which will check mail server configurations.

Huh, comes up with a cert warning. Looks like it's expired.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact