What it checks
Whether the site publishes /.well-known/security.txt, and whether it has the Contact and Expires lines RFC 9116 requires, with an expiry still in the future.
A pass means: A valid security.txt tells researchers how to report problems.
Possible findings
No security.txt
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
No security.txt file was found at /.well-known/security.txt.
Why it matters
security.txt tells researchers who find a problem how to report it to you, rather than leaving them to guess or give up.
How to fix it
Publish /.well-known/security.txt with at least a Contact and an Expires line, for example Contact: mailto:security@example.com and Expires: 2027-12-31T23:59:59Z.
security.txt is incomplete or expired
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
A security.txt file exists but is missing a required field or has expired.
Why it matters
Researchers may ignore an expired or incomplete file, or be unable to reach you.
How to fix it
Make sure the file has at least one Contact line and an Expires date in the future (RFC 9116), and set a reminder to update it.

