All Security Checks
Infrastructure CheckA05:2021

Netlify Hosting Security Scanner

Check Netlify-specific security configuration, headers, and deployment settings.

Netlify-hosted sites have platform-specific security settings that are often overlooked. Our scanner checks for proper _headers configuration, redirect rules, deploy preview access, and Netlify-specific security features.

What This Scanner Does

Detects Netlify hosting and checks _headers file configuration, _redirects rules for open redirect risks, deploy preview authentication, form handling security, and serverless function exposure.

Why It Matters

Netlify's default configuration may not include all recommended security headers. Deploy previews can expose unreleased features, and Netlify Forms can be abused for spam without proper configuration.

Common Findings

  • Missing _headers file for security headers
  • Deploy previews publicly accessible
  • Open redirect in _redirects configuration
  • Netlify Forms without spam protection

OWASP Top 10 Coverage

A05:2021Security Misconfiguration

Run This Check on Your Site

Get a full security report with AI-powered fix suggestions in 30 seconds. No setup required.

Related Security Checks