A website security check that explains itself in plain English. Free, no key, observation only.
npx everthread check yourbakery.com
EverThread · yourbakery.com
WORTH A LOOK Nothing alarming, but one thing is worth fixing.
FIX THIS WEEK Your site lets browsers fall back to an insecure connection
The Strict-Transport-Security header is not being sent. ...
Fix: Send the technical line below to whoever runs your site. ...
- One fresh check per site per week. Inside that week you get the stored result, its age, and a note about daily watching.
--jsonfor machines,--fail-on urgent(orattention) to fail a CI step.everthread explain tls.expiringandeverthread findingsfor the explanations behind every finding.
{ "mcpServers": { "everthread": { "command": "npx", "args": ["-y", "everthread", "mcp"] } } }Tools: check_site, explain_finding, list_findings. Works with Claude Code, Claude Desktop, Cursor, and anything else that speaks MCP.
It loads the home page the way a browser does and reads the certificate, security headers, scripts, forms, frames, redirects, a fixed handful of well-known files, and the page text. It never logs in, probes for hidden paths, or runs exploit tooling. Public results withhold the exact address of an exposed file; the site owner sees it after signing up. Only check sites you own or have permission to check.
Docs: https://everthread.live/api · Every finding explained: https://everthread.live/fix/