Website security check
Certificates, headers, cookie flags and open ports, read the way an outsider reads them.
Checks run in parallel, and slow ones time out rather than hold up the rest.
What gets checked
SSL Certificate
Certificate issuer, validity dates and the chain of trust
Headers
Every HTTP response header the server sends back
Open Ports
Which common ports are open and reachable on the host
Vulnerabilities
CVEs Shodan links to the services running on the host
DNSSEC
DNSSEC records proving DNS answers have not been tampered with
HSTS
Whether browsers are told to only ever connect over HTTPS
Security.txt
The security.txt file, and who it says to contact about vulnerabilities
Firewall
Which web application firewall, if any, sits in front of the site
HTTP Security
Protective headers such as CSP, X-Frame-Options and nosniff
Block Detection
Whether privacy, malware and parental-control resolvers block the site
Malware & Phishing
Whether the site appears on common malware and phishing lists
TLS Connection
The version, cipher suite and details of a live TLS handshake
TLS Security Audit
SSL Labs' grade for the server's TLS configuration
TLS Client Compatibility
Whether Chrome, Safari, Java and older Android can still connect
What this tells you
Most of a site's security posture is public. Certificates, response headers, cookie flags and listening ports get handed to anyone who asks, including whoever is working out whether you're worth the effort.
None of it needs access to the site. That's rather the point: if you can see it from here, so can everybody else.