A 24-item website security audit with a plain-language report
Know what your site exposes before a customer, a competitor or a bot does.
Overview
The check on our homepage sees 8–10 items from a single request. The full report covers 24 items across security, mobile speed and compliance with Thailand's Personal Data Protection Act, written so a business owner understands it and the person who maintains your site can act on it immediately.
The audit is strictly passive: we read what the site sends to any ordinary visitor plus public records. No probing, no vulnerability testing, no unusual requests. Nothing needs permission from your host and nothing puts your systems at risk.
Fix the issues and watch the result change
The response headers of a typical SME site. Toggle each issue to fixed to see the correct value, then run the real check on your own site below.
Score
Grade F
2 risks · 5 to fix · 0 passed
Issues found
Tap an issue to see the fix
What the server sends back sample-shop.co.th
HTTP/2 200 content-type: text/html; charset=utf-8 server: Apache/2.4.29 (Ubuntu) x-powered-by: PHP/7.2.34 set-cookie: PHPSESSID=9f1c…; path=/
How to fix · Encrypted connection not enforced (HSTS)
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
Check your real site
Who it is for
- Business owners with an existing site who are not sure what the developer left behind
- Businesses changing web vendors who want to know the state before taking over
- Organisations that must answer PDPA questions from customers, partners or legal
- Anyone who ran the homepage check and saw red
What you get
- 01A 10–15 page PDF report in Thai (English on request): a one-page executive summary, 24 findings with risk levels, evidence, and fixes in priority order
- 02A worksheet you can hand straight to your team or existing vendor
- 03One free re-check after fixes, within 60 days
- 04A 30-minute call to walk through the results
The 24 items
Transport and header security
- 01TLS configuration and certificate: version, expiry, chain
- 02HTTPS enforcement (HSTS) and HTTP redirects
- 03Content-Security-Policy
- 04Clickjacking protection
- 05MIME-sniffing protection (X-Content-Type-Options)
- 06Referrer-Policy
- 07Permissions-Policy
- 08Cookie flags: Secure, HttpOnly, SameSite
- 09Software, CMS and plugin version disclosure
- 10Mixed content and unsafe outbound links
DNS and domain email
- 11SPF: who may send email as your domain
- 12DKIM: signatures proving mail really came from you
- 13DMARC: protection against email spoofing in your company's name
- 14CAA records and abandoned subdomains open to takeover
Mobile speed
- 15Largest Contentful Paint on 4G
- 16Layout shift during load (CLS)
- 17Responsiveness to taps (INP)
- 18Image and JavaScript weight
- 19Server caching and compression
PDPA and trust signals
- 20Thai privacy notice and completeness under Section 23
- 21Form consent: not pre-ticked, purpose stated
- 22Cookie banner and trackers loading before consent
- 23Third-party trackers and cross-border data transfer
- 24Required business identity: legal name, registration number, address, contact
How it works
- 01
Send the address and pay
On LINE or the form. ฿6,900 by PromptPay or transfer.
- 02
Audit within 3 working days
Passive only. No passwords or access of any kind required.
- 03
Report and a 30-minute call
Results in plain language, with what to fix first.
- 04
Re-check after fixes
One free re-check within 60 days.
Price
Questions
+–Do you need passwords or server access?
No. All 24 items use only what the site sends to any visitor plus public records such as DNS. Deeper testing that requires access is a separate service with a contract and written authorisation.
+–How is this different from free online scanners?
Free tools tell you which header is missing. Our report tells you what that means for your business, what to fix first, and how to fix it on the platform you actually use, including the PDPA items no automated tool checks.
+–What if the results are bad?
That is normal. Most sites we audit have at least five risk items. The report orders what needs fixing now and what can wait. Take it to your existing vendor, or let us fix it under the care plan.
Send us the address to audit
LINE is easiest. We reply with payment details and the report date.
