Oxwyn Studio

Free X-Ray

Find out what your website is telling strangers.

Type your address and we run a real scan: the security headers your server sends, the certificate behind your padlock, whether anyone can send email as your domain, the software versions your pages publish, and Google's own speed and accessibility scores. It takes under two minutes and every number is a measurement, not an estimate.

We read the page, its headers, its certificate and its public DNS records. We do not log in, we do not probe admin paths, and we identify ourselves in your server logs as OxwynXRay.

What we check

Security headers

The six defensive headers a browser looks for, read straight off your server's response, plus the Secure, HttpOnly and SameSite flags on every cookie you set. They are free, they are set once at the host, and they are the cheapest protective work available on any website.

Your TLS certificate

We open a real connection and read the certificate: who issued it, when it expires and whether the chain validates. An expiring certificate is the failure that takes a business offline with no warning, and the owner usually hears about it from a customer.

Email authentication

SPF and DMARC on your domain, which decide whether a stranger can send email that appears to come from your address. Almost nobody checks this, and invoice fraud against small businesses usually starts exactly there.

What your site tells attackers

Many sites publish their exact platform version, and the version of every add-on, in their own page source. It is a component inventory, free to anyone, and its owner has usually never seen it.

Google's own speed scores

A full Lighthouse run on a simulated mid-range phone: performance, accessibility, technical SEO and best practices, plus the Core Web Vitals Google reports in Search Console.

Findability and privacy

Titles, descriptions, structured data, sitemap and robots, plus whether the http address and the www address both answer independently. And how many cookies you set and how many third-party trackers load before a visitor has consented to anything.

AI visibility

Whether robots.txt lets the assistant crawlers in, how much of your content exists before JavaScript runs, and whether your address, hours and answers are published as data an assistant can lift rather than prose it has to interpret. Nobody has published a ranking algorithm for AI answers, so we check the mechanics and do not pretend to know the rest.

Where we stop

We only read what your site publishes for anyone to read. We do not probe login pages, admin panels, backup files or configuration paths, and we do not test a weakness by trying to exploit it. Scanning a stranger's private paths without permission is unauthorised access under the Computer Misuse Act 1990, and a studio that asks clients to sign a Data Processing Agreement should not be doing it from a form on its own home page.

Questions

Is the full report really free?
Yes. The whole report is written before you are asked for anything, and the email address opens what already exists. We ask for it because this is how the studio finds clients, and it would be dishonest to pretend otherwise.
Are you hacking my website?
No. Every check reads something your site publishes to any visitor: the page itself, its response headers, its certificate, its public DNS records, and the conventional files at robots.txt, sitemap.xml and security.txt. We never log in, never probe admin paths and never test for a vulnerability by trying to exploit it. Our requests identify themselves as OxwynXRay in your server logs.
Can I scan a site I do not own?
Technically yes, because everything we read is public. But the report is written for the person who can act on it, and we would rather you sent the address of your own site.
How accurate is it?
Every finding is something we measured at the moment of the scan. Where a check cannot run, the report says so and that area is left unscored rather than marked down. What it will not find is anything requiring a login, a code review or a penetration test, and it does not pretend to.
Does an artificial intelligence write the report?
No. Every measurement, every score and every finding is produced by code and would be identical without any AI involved. One paragraph, the plain-English summary at the top of the full report, is written by a language model from those measurements, it is labelled as such on the page, and it cannot add a finding or a number.
What do you do with my email address?
One person reads it and may write back once. There is no newsletter, no automated sequence and no reselling. It is stored with the scan so we know which report you asked about.

If the report finds things you would rather not deal with yourself, the monthly plans include the patching, the certificates and the monitoring, with prices published before you make contact.