Matan · Security · Exposure

security.txt

RFC 9116: publish a contact for vulnerability reports at /.well-known/security.txt.

Pass condition in our engine: A security.txt file is reachable (well-known or /security.txt).

1. Problem description

Researchers look here before filing a public advisory. Missing the file does not mean you are vulnerable; it means they may tweet instead of emailing you. Optional but cheap.

2. Most common causes

  • Never created.
  • Only /security.txt at the root without the well-known path.

3. How to fix it

  1. Add /.well-known/security.txt with Contact: mailto:security@… and Expires:.
  2. Optionally list Policy and Canonical.
  3. Keep the date in the future.

Test this check

We fetch only this URL (plus robots.txt / llms.txt at the domain root when the check needs them). We do not crawl the rest of the site like a full report.

Scoring rules for the full site crawl are documented in methodology. Want every category at once? Generate a free report.

Get your free SEO & GEO report

Enter your URL and receive a full audit with scoring and recommendations. No sign-up required.