0
0 Comments

Introduction

Every major company—Google, GitHub, Cloudflare—has a security.txt file. Most smaller companies don't, and when they do, it's often misconfigured, expired, or missing required fields.

I built SecurityText Check because reporting a vulnerability should never be harder than finding one. Security researchers waste hours hunting for the right contact when a simple, standardized file at /.well-known/security.txt would solve it instantly. RFC 9116 exists, but adoption is low because there's no easy way to generate a compliant file, validate existing ones, or catch when they silently break.

SecurityText Check makes it dead simple: paste, generate, or point it at any domain — get instant validation with plain-English fixes. No signup required, everything runs in-browser, and monitoring keeps your file from going stale. It's the tool I wished existed every time I saw a broken or missing security.txt in the wild.

Premium Features for multiple domains monitoring, email alerts and more available.

posted toAvatar for product SecurityTextCheck
SecurityTextCheck