Passive public-website checks · Built for small teams

The practical first security check for small businesses.

Find the security weaknesses your website is exposing publicly.

You don’t need a security team or an enterprise budget to know if your website is exposed. ThreatSense quietly checks what the public can see about your site, then tells you the few things worth fixing first, with why each matters and who should fix it. No logins, no intrusive scanning, no jargon.

Passive checks only
NVD · KEV · EPSS · OSV enrichment
£27 full report · no subscription
ThreatSense passive website attack-surface check showing scores and findings

Hygiene

70

Tech exposure

65

Overall

73

Illustrative example, not a real customer result

60%+

of breaches involve a known, unpatched vulnerability

Industry finding from Verizon DBIR and similar breach reports: many exploited flaws had a patch available. Source: public industry breach reports.

1,000s

of new CVEs published every month

The NIST NVD publishes thousands of new vulnerability records each month. Source: NIST NVD public statistics.

0

logins, passwords or intrusive scans required

ThreatSense only reads what the public can already see. We never log in to your systems or run active exploit attempts against your site.

Statistics are widely-reported industry figures with sources cited, not ThreatSense customer results. We do not claim to predict real-world exploitation.

The Platform

Built for owners and small teams, not security experts

Every feature exists to answer one question: what can the public see about my website, and what should I fix first?

Just enter your website address

No software to install, no logins to share, no technical setup. Type your domain and ThreatSense checks what the public can see: security headers, your certificate, email records and exposed software.

A security check you can run yourself in under a minute.

A short list of what to fix first

Instead of a wall of jargon, you get your top three actions in plain English, with why each matters to your business, how urgent it is, roughly how much effort it takes and who should fix it.

Know what to do next without needing a security expert.

Honest, evidence-based scores

Seven scores (website hygiene, email setup, technology exposure, CVE evidence and more), each with a plain-English explanation of why it changed. Missing data is labelled 'not checked', never a failing score.

Trust the number because you can see how it was made.

See what attackers see

Find out which technologies and versions your site exposes, whether an admin path is reachable, and what public records say about your services. All observations, never exploit attempts.

Shrink your attack surface by removing what shouldn't be public.

A full report you can hand to a developer

Unlock the full report for a one-off £27 (no subscription). Every finding comes with evidence, source, date, confidence, severity, recommended action, estimated effort and who should fix it. Download it as PDF or JSON.

Hand your developer a clear, complete action plan.

Safe by design

ThreatSense only looks at public information, the same things anyone on the internet can see. It never logs in to your systems, crawls private areas or runs intrusive scans. Private addresses are blocked.

No risk to your site, no surprises.

ThreatSense is not a penetration test, a vulnerability scanner, a SOC or a guarantee that a site is secure. It is a passive, evidence-based check of your public website and domain.

The Scoring Engine

Scores that show what to fix, and why

Each score is computed from real, evidence-based observations and recomputed every time you check. We use public threat-intelligence sources (NVD, CISA KEV, EPSS, OSV) to add context. Missing data is labelled “not checked”, never a failing score.

Public website

HTTP headers · TLS · redirects

DNS & email

SPF · DMARC · DKIM · MX

Threat intel

NVD · CISA KEV · EPSS · OSV

Scoring Engine

example.com · passive scan

Hygiene

70

Tech exposure

65

Overall

73

Why these scores:

2 header findings (HSTS, Referrer-Policy) reduced hygiene. 4 technologies detected with exposed versions. No CVEs in CISA KEV. Missing data excluded, not penalised.

Illustrative example, not a real customer result

From the people using it

Real stories, when we have them

Placeholder quotes: replace with real customer testimonials before launch.

[Placeholder: replace with a real customer quote. Example angle: how ThreatSense showed a small business owner the few things worth fixing on their website, in plain English.]

Placeholder · Small business owner

[Placeholder: replace with a real customer quote. Example angle: an office manager on finally understanding their website's security without needing a security team.]

Placeholder · Office manager

[Placeholder: replace with a real customer quote. Example angle: a small IT provider on using ThreatSense across a few client websites to prioritise fixes.]

Placeholder · IT provider

Pricing

Start free. Pay £27 for the full report.

No subscription required. Run a free check, see your top three actions, then unlock the complete report for a one-off £27 when you want the full evidence and action plan.

Free Check

Quick overview of what your website is exposing publicly.

£0free, no card
  • Overall ThreatSense score
  • Your three most important findings
  • Short explanation of business impact
  • Top actions in plain English
  • Clear invitation to purchase the full report
Run your free check
Most popular

Full Report

Complete evidence and a full action plan you can hand to your developer.

£27one-off · no subscription
  • Complete findings (not just the top 3)
  • Evidence and source for every finding
  • Date checked and confidence level
  • Business impact, severity and recommended action
  • Estimated effort and who should fix it
  • What was not checked, labelled honestly
  • Downloadable PDF and JSON
  • Clear Proxaim Full Remediation Package CTA
Unlock the full report

Future Monitoring

Ongoing checks and alerts so you stay on top of changes.

Plannedroadmap
  • Multiple monitored domains
  • Scheduled scans (weekly or monthly)
  • Scan history and trend tracking
  • Email alerts on material change
  • Remediation tracking
  • Deeper technology discovery
  • Optional paid intelligence providers
  • Priority support
Planned

On the roadmap. Not yet available.

How it fits together

Free Check

Quick overview.

Full Report

Complete evidence and action plan.

Full Remediation Package

Proxaim fixes the issues for you.

Future Monitoring

Ongoing checks and alerts.

The full report is a one-off £27 payment in GBP. No subscription, no recurring charge. ThreatSense is a passive public-website checker, not a replacement for a penetration test, vulnerability scanner or SOC. Need help fixing the issues found? Ask about the Proxaim Full Remediation Package.

FAQ

Straight answers for small teams

Yes. You enter your website address, run a free check, and get a one-page summary: your overall score and top three actions in plain English, why each matters to your business, how urgent it is, roughly how much effort it takes and who should fix it. For the complete picture, unlock the full report for a one-off £27 and download it as a PDF to hand to your web developer or IT contact. You never need to share passwords or log in to your site.

See what the public can see about your website.

Run a free check and get your top three actions in plain English. Unlock the full report for £27 when you want the complete evidence and action plan. No subscription, no card to start.

ThreatSense is a passive public-website checker for small businesses and small teams. Not a replacement for a penetration test or a security operations centre.