Scanner · TLS

Hosted testssl.sh
TLS configuration auditing, hosted.
testssl.sh is the de facto standard for checking TLS/SSL configuration on any internet-facing service. It checks every relevant protocol version, cipher suite, certificate chain detail, and known TLS vulnerability. One credit. One TLS audit. One PDF report.
What it checks
TLS protocol detection
Identifies every supported TLS version (SSLv2 through TLS 1.3) and flags deprecated or insecure protocols that should be disabled.
Cipher suite analysis
Enumerates all cipher suites the server advertises, graded by cryptographic strength. Highlights weak, export-grade, and anonymous ciphers.
Certificate chain validation
Checks the full certificate chain for trust store issues, expired certificates, hostname mismatches, and weak signature algorithms.
Known attack detection
Tests for 20+ known TLS vulnerabilities including Heartbleed, ROBOT, LOGJAM, FREAK, POODLE, BEAST, CRIME, and Ticketbleed.
Forward secrecy check
Evaluates whether the server supports ECDHE key exchange for perfect forward secrecy, and whether DHE parameters use safe prime sizes.
HSTS & security headers
Checks for HTTP Strict-Transport-Security headers and evaluates the server's HTTP/2 and ALPN support.
Why hosted
Zero install
testssl.sh needs Bash, OpenSSL, and a handful of utilities to run. Skip the dependency chase — we manage it on the scanning host.
Stateless audits
Each scan is a fresh audit against the target. No results stored between scans — your TLS posture data stays private to your account.
PDF reports
Every TLS scan generates a branded PDF report with findings ranked by severity, remediation guidance, and references — ready to hand to a client or auditor.
Single credit
One TLS audit costs one credit. No per-port billing — scan the full TLS configuration for a flat credit.
About the project
testssl.sh is an open-source TLS/SSL configuration assessment tool written in Bash by Dirk Wetter and the community. It requires no compilation or installation — just a shell and OpenSSL. It checks 100+ configuration parameters across every major TLS attack surface.
Run a full TLS audit against any host and port — one credit, one PDF report.
Run a TLS audit →