01 OVERVIEW
Two separate questions. Security is how likely you are to actually get compromised — mostly a question of whether your software is patched and your connection is sound. Trackability is how easily advertisers and data brokers can recognise you across sites. They are not the same thing, so they are scored separately.
Running checks…
Running checks…
Running checks…
Most important findings
- Working…
02 DEVICE & OS
Your hardware profile, and whether your operating system is still receiving security updates. An unsupported OS is the single biggest risk on this page — it means new vulnerabilities simply never get fixed.
03 BROWSER
Which browser you are running, whether it is current, and whether you are actually inside an app's built-in browser rather than a real one — which matters, because an in-app browser can watch everything you type.
Automation signals
How many markers associated with automated or headless browsers your setup exposes. These have real false positives — virtual machines, remote desktop, accessibility tools and hardened browsers all trip them — so this is a list of signals, not a verdict.
04 NETWORK
Where your traffic appears to come from, who carries it, and how well protected the connection itself is.
Connection type
Browsers deliberately hide whether you are on WiFi or cellular — it was too useful for fingerprinting. So this is inferred from who owns your IP address and how your connection behaves, and is labelled as an inference rather than a fact.
DNS & privacy relays
05 SPEED TEST
Measures download, upload, latency and jitter against Cloudflare's public speed endpoints. This is the only part of the page that moves a meaningful amount of data — roughly 30 MB — so it only runs when you ask it to.
06 FINGERPRINT
Sites can combine small, individually harmless details into a signature that identifies your browser without any cookies. Below is what this page could read, and roughly how distinctive the combination is.
Safari and Firefox now deliberately add random noise to several of these, so a signature that changes between sessions is a sign your browser is defending you — not a failure. This is a per-session value and is not stored.
07 EXPOSURE
What this browser is willing to hand a website, and what it has already been granted. Every capability here is checked by feature detection only — nothing on this page asks your browser for a permission or shows you a prompt.
Powerful hardware APIs
These let a site talk to physical devices. All require your explicit approval before they do anything, so their presence is attack surface rather than active risk — but a browser that exposes fewer of them has less that can go wrong.
Current permissions
Storage & devices
Page embedding
08 PRIVACY
Whether your browser is set up to resist tracking, and which signals it sends on your behalf.
Private browsing detection
Sites are not supposed to be able to tell whether you are in a private window, but several techniques still work — which is worth knowing, because sites do use them. This check takes about a second of measurement, so it is opt-in.
09 WHAT TO FIX
Built from what was actually found on this machine, ordered by how much real-world risk each one carries. The top of this list is worth more than everything below it combined.
- Working…
10 DOMAIN CHECK
A bonus tool, and the one thing here that is not about your machine. Enter a domain to check whether it is protected against email spoofing — that is, whether someone can send mail that convincingly claims to be from it.
The domain you type is sent from your browser to Cloudflare's public DNS resolver
(cloudflare-dns.com) to look up its records. Nothing else leaves the page.