Smart Deals - promotions, discount codes and sales

Security TXT Metadata Check

Fast, accurate and free online security txt metadata check tool running directly in your browser.

Secure (SSL)
Client-Side Processing
100% Free
Instructions
  • 1
    Enter data
    Enter content, paste text or load a file from disk.
  • 2
    Click the button
    The tool will immediately process your data in the browser.
  • 3
    Get the result
    Copy the finished text or save the file to your device.
function runTool() {
  return "Result ready in 0.1s";
}

Security TXT & Metadata Check

This tool tries to find the security.txt file for the specified domain, extracts contact information from it for reporting vulnerabilities, and at the same time scans typical metadata files (humans.txt, robots.txt, changelog, readme, etc.). All this to quickly assess security hygiene and the amount of information disclosed about the application.

Trying to find security.txt and scanning typical metadata files...

No obvious security.txt or metadata issues were found. Remember that this is just a simple external check - a full security review requires a broader audit of applications and infrastructure.

Rate this tool:

Related tools

Other tools you may find useful

Security.txt metadata checker - check how your website communicates security

Security.txt metadata checker is a practical online tool that automatically searches and analyzes thesecurity.txtfile associated with a given website, and then clearly shows whether the contact details for the security team, the vulnerability reporting policy and security metadata are correctly configured and up to date. You don't need to know the RFC standard, just enter the website address and the scanner will do the rest.

Analysis of security.txt file
Quick validation of security metadata
Detecting errors in Contact, Encryption, Policy fields
Support for standard path /.well-known/security.txt

What does Security.txt metadata checker do in practice

The tool works as an intelligent reader of the security.txt file, which in the background downloads security metadata from the website, organizes them by fields and checks whether they comply with the adopted standard. Instead of manually opening addresses in the browser, copying the content and trying to interpret individual lines, you immediately see a clear report that shows the most important elements in a form that is understandable even outside the security team.

  • Automatically checks common paths, especially/.well-known/security.txt.
  • Analyzes the structure of the security.txt file and recognizes standard fields such as Contact, Encryption, Policy, Acknowledgments, Hiring, Expires and Preferred-Languages.
  • Verifies that the Contact field contains valid contact addresses, for example e-mail, form URL or other reporting channel.
  • Checks for the presence of encryption key information in the Encryption field, which facilitates the secure transmission of sensitive vulnerability details.
  • Finds a link to the vulnerability reporting policy in the Policy field, so users know how to report issues step by step.
  • Will evaluate the expiration date from the Expires field, suggesting whether the security.txt file is current or needs to be refreshed.

With this, Security.txt metadata checker allows you to see with one click how your site is communicating with the security research community and whether it is providing all the key information needed to report vulnerabilities responsibly.

How to use the security.txt analyzer step by step

The tool has been designed to be used by both a security specialist and a person who is just starting to be interested in responsible disclosure. Just enter the website or domain address and the scanner will take care of the rest and display the results in an understandable layout.

  1. In the form field, enter the website address, for examplehttps://yourdomain.plor simplyyourdomena.pl.
  2. The tool will automatically clean the address of unnecessary elements, focusing on the right domain.
  3. Run the scan, then wait a while while the tool tries to download the security.txt file from the usual locations.
  4. If the file is found, you will see a summary, a list of detected fields and their detailed content.
  5. Below you will find warnings and recommendations, such as missing Expires, missing Contact, or outdated metadata.
  6. If a security.txt file is missing, the tool will clearly indicate this and suggest implementing such a file as a good practice.

All analysis is just reading publicly available metadata, without any testing of applications or services, so Security.txt metadata checker is perfect for quick, repeatable checks and work on larger projects and domain portfolios.

What security.txt fields are checked by

The security.txt standard is based on a set of simple fields that together create clear instructions for people who want to report a vulnerability or contact the security team. The analyzer groups these fields into a clear table, so you can immediately see which elements are present and which are worth adding.

Field Purpose What the report shows
Contact Primary contact details for the security team or vulnerability reporting channel. A list of e-mail addresses, form URLs, or other contacts, along with whether the format looks correct.
Encryption Information about the encryption key, for example a link to the PGP key. The key address and a signal that reporters can provide sensitive details in an encrypted manner.
Policy Link to the vulnerability reporting or responsible disclosure policy. URL of the policy and a suggestion that it is worth keeping it up-to-date and understandable.
Acknowledgments Information about the people or teams you thank for reporting vulnerabilities. The address of the page with thanks to researchers, which positively affects cooperation with the community.
Hiring Optional link to security job postings. The address to the career section, which allows interested researchers to join the team.
Expires The date until which the security.txt metadata is considered current. A specific date and information whether the date is expired, which affects the reliability of the file.
Preferred-Languages ​​ The languages ​​in which you prefer to receive vulnerability reports. List of languages ​​and help in tailoring communication to the team that handles requests.

Report summary and security.txt quality assessment

The fact that you have a security.txt file is only the first step. Security.txt metadata checker also focuses on assessing the quality of metadata, so that the report can immediately see whether the file is complete, up-to-date and whether it contains all the key information needed for comfortable reporting of vulnerabilities.

Assessment of completeness and currency of metadata

At the top of the report, you see a synthetic assessment in the form of a simple description that brings together the main conclusions from the analysis. This means you don't have to dig into every line of the security.txt file to see if everything looks OK.

  • Information whether the security.txt file was found in the standard location and whether it was read correctly.
  • Assess whether the most important fields such as Contact, Policy and Expires are present and filled in correctly.
  • Message when Expires points to a date in the past, indicating that metadata needs to be updated.
  • Suggestion that you might want to add missing fields, such as Encryption, if you want to enable encrypted reporting.

Such a quick assessment helps those responsible for the domain decide whether a minor tweak to the security.txt file is enough or whether a major update to the security contact policy is needed.

Warnings and practical recommendations

In addition to the list of fields, the tool generates clear warnings where it notices an imbalance between the theory of the security.txt standard and the practical comfort of those reporting vulnerabilities. As a result, the report is not only a collection of data, but also a short list of tips.

  • Warning if the file is missing the Contact field or the entry is in a format that is difficult to use in practice.
  • Recommendation to add the Policy field if the vulnerability reporting policy is described only elsewhere.
  • The message that Expires indicates a very distant future or does not occur at all, which reduces the clarity of the file.
  • Hint that Preferred-Languages ​​can make communication easier if your team handles tickets in multiple languages.

This makes Security.txt metadata checker a great tool for people who are just implementing the security.txt file, as well as for experienced teams who just want to quickly confirm that everything is still in line with best practices.

When is it worth running security.txt analysis

Security.txt metadata checker fits well into the everyday work of people dealing with security, but it is also useful for administrators, website owners and marketing teams who care about the image of the brand as conscious and responsible. In many situations, one quick check of the security.txt file can avoid communication chaos when reporting a serious vulnerability.

Typical usage scenarios

  • Taking over a new domain or website and quickly verifying whether security.txt is present and up to date.
  • Implementation of the new responsible disclosure policy and checking whether the link to the policy has been added correctly.
  • Periodic security reviews where you want to check the consistency of security metadata.
  • An audit of the organization's domain portfolio to identify those sites that do not yet have security.txt.

In each of these cases, the tool allows you to significantly speed up your work because it eliminates manual clicking on addresses and focuses on a simple, tabular report that can be easily shared among the team.

Safe and ethical use of the

tool The analyzer uses only publicly available metadata that the website consciously makes available, but like any security-related tool, it should be used responsibly. It provides the most benefits when it is used to protect and organize your own resources and services audited with the consent of the owner.

  • Focus primarily on domains that you are responsible for or support professionally.
  • For customer projects, ensure security metadata checking is included in the scope of work.
  • Treat the report as support for implementing and updating security policy, not as an offensive tool.
  • Remember that security.txt is just one piece of a larger puzzle that includes application, infrastructure and process testing.

This approach makes the Security.txt metadata checker a natural element of a responsible approach to security, and not just a one-off gadget used during an incident.

Security.txt metadata checker FAQ

Does the tool modify the security.txt file in any way on the server

No. Security.txt metadata checker works only in read mode. Retrieves the content of the security.txt file using a standard HTTP request, parses it on the tool side and presents the result in the form of a report. No data on the target server is changed or overwritten.

What happens if my site doesn't have a security.txt file

If the tool doesn't find a security.txt file in common locations, it will clearly indicate this in the scan results. In the report, you will then see a message about the lack of security metadata, along with a suggestion to implement it, so that people who want to report a vulnerability will not have to look for contact on their own.

Is one correct security.txt enough to consider the website safe

The mere fact of having a security.txt file does not mean that the application or infrastructure is free from vulnerabilities. First of all, it is a signal that the organization cares about transparent communication in the area of ​​security and provides a clear reporting channel. Therefore, treat the analyzer report as part of a larger set of security actions, not as a final judgment.

How often should you update security.txt and rescan

It is a good idea to update the security.txt file whenever there is a major change to the contact, vulnerability reporting policy or responsibility structure in the team. Re-running the scanner after changes ensures that the new data is visible, and the Expires field shows a realistic deadline so that no one is left in any doubt as to whether the metadata is still up-to-date.

Remember that security.txt is primarily a communication tool with people who want to responsibly report security issues. The more readable and up-to-date the metadata, the easier it is to build trust between the technical team and the community of users and researchers.

Check what the security.txt file says about your website

Enter the website address in the field above the tool, run the Security.txt metadata checker and in a few seconds see whether the security team contact, vulnerability reporting policy and Expires metadata are configured transparently and in line with good practices.

One scan, clear report and specific recommendations for implementation.
Install Webp.pl Have the tools in your own pocket!