Use case
Level 2 / ContextSecurity disclosure
security.txt tells a researcher how to report a vulnerability. RFC 9116 requires an expiry date so stale contacts stop being trusted, which means a file nobody renews fails on a date you could have known.
Without a check
What goes wrong
- Expires passes and the file stops counting, usually discovered in an audit.
- The file is served from the wrong path, or as an HTML page.
- Expires is set years ahead, which RFC 9116 advises against.
With Flowpane
What changes
- Scores an expired file at zero. It is a hard rule, not a warning.
- Flags files that expire within 30 days, and expiry dates more than a year ahead.
- Checks required fields, date formats, and the canonical location.
What it looks like in Flowpane
Illustrative- Warningsecurity.txtExpires in 21 days.
- Warningsecurity.txtExpires is more than a year away.
- Advicesecurity.txtAdd Canonical and Preferred-Languages.
Level 3 / Method
How each check works.
Each file, how it fails in public, what true looks like, and exactly how it is checked.
security.txtsecurity.txtsecurity.txt tells researchers where to report a vulnerability. RFC 9116 requires a Contact and an Expires date, and an expired file scores 0.ReadScoringHow the score worksFlowpane scores each of eight artefacts from 0 to 100, then weights them into one site score. Only the next public check moves it. Drafts and errors never do.ReadCrawler identityHow Flowpane fetchesFlowpane reads public HTTPS only, never signs in, and signs requests with Web Bot Auth so firewalls can verify them. Blocked is never reported as Missing.Read
See what your sites are claiming.
Add an origin and get a score, the gaps, and the evidence behind each one. Then Flowpane keeps checking, so the answer stays current.
Free during the beta. Flowpane only reads your origin.