The short answer
| Run | Verdict | What it said |
|---|---|---|
| 2026-10-05, first live run | exposed | 1 medium risk: http://tools.openkrill.app/ answered 200 with no redirect. 8 leak paths answered 404. |
| 2026-10-08 03:12 UTC | exposed | The same medium risk, now with the backend signals added: 34 requests in total. |
| 2026-10-08 03:55 UTC, after the fix | clean | 0 high or medium risks, 34 requests. Plain http now answers 301 to https. |
Why plain http mattered when we already sent HSTS
Our https answers already carried Strict-Transport-Security: max-age=31536000; includeSubDomains. HSTS tells a browser to use only https for a host, but only after it has seen that header once over https (RFC 6797, Hodges, Jackson and Barth, 2012). A first visit typed as http, a link in an old email, curl or an AI agent never saw the header, so they got the whole page over plain http. The OWASP testing guide checks HSTS for exactly this gap (OWASP WSTG v4.2, Test HTTP Strict Transport Security).
The fix, and why we did not flip the zone switch
Cloudflare has one setting that sends every http request on a zone to https (Cloudflare, Always Use HTTPS). It is zone-wide, so it would also change hosts on openkrill.app that are not this site. We chose a narrower rule in the site's own Worker: a GET or HEAD over http gets a 301 to the same path and query on https, and any other method gets a 308, so a form post is not turned into a GET. It went live on 2026-10-08, and the next Site Check run came back clean.
What the clean run read
- Leak paths. 15 known leak paths, such as
/.git/HEAD,/.envand/docker-compose.yml, and 4 admin paths, such as/adminand/phpmyadmin/. All answered 404. - Scripts. The page's script was read for keys and source maps. None found.
- Backend signals. CORS pass, bad request pass, no stack trace, no token in error pages. No health check was found, so that item is marked as needs verification, not as a failure. Our site has no sign-in, so the login rate limit was not checked. The backend readiness checklist post explains each signal.
- Subdomains. crt.sh answered 502 on this run, so certificate names were not read. The tool said so in its answer instead of reporting zero subdomains.
Subdomains, from the first run
Certificate Transparency logs list every public certificate, so anyone can list the names a domain has used (RFC 6962, Laurie, Langley and Kasper, 2013). A name that still points at a service you no longer run can be taken over (OWASP WSTG v4.2, Test for Subdomain Takeover). On 2026-10-05, crt.sh listed 13 live certificates with 10 names for openkrill.app. All 10 resolved, and none was a dangling CNAME.
By hand versus the tool
Before we trusted the tool, we did the same checks by hand on 2026-10-05: a crt.sh query, a DNS lookup per name, 8 leak paths, the https headers and the http answer. That took about 23 requests over 5 tools and 56 seconds of command time, not counting the time to know which checks to run. The by-hand run also made a real mistake: a shell loop dropped the last subdomain because the file had no final newline, and we only caught it by counting. The tool does it in one call, with a fixed path list and the answer first: verdict, top risks and a fix for each.
What it cannot see
Site Check does not scan ports: the only free passive port source we checked does not allow use in a paid product, and an active scan is out of bounds. It never signs in and never loads the site. The 12 backend items that live in code, such as access between users and tested backups, come back as a list for you to check, with the way to check each. And it only reads a host after its owner publishes a proof token, so you cannot point it at someone else's site.
Try it: run the same check on a host you own in one call. Open Site Check, or add it in Claude, ChatGPT, Cursor or Pi. The 16 items are also on the backend readiness checklist.
Sources
- Hodges, Jackson, Barth. RFC 6797, HTTP Strict Transport Security (2012): HSTS makes a browser use only https, after it has seen the header once.
- OWASP WSTG v4.2, Test HTTP Strict Transport Security: how to test HSTS max-age and includeSubDomains.
- Cloudflare docs, Always Use HTTPS: one zone setting redirects every http request to https.
- Laurie, Langley, Kasper. RFC 6962, Certificate Transparency (2013): public logs list every issued certificate.
- OWASP WSTG v4.2, Test for Subdomain Takeover: dangling DNS records let someone take over a subdomain.
- Our own runs: Site Check
exposure_checkon tools.openkrill.app, 2026-10-05, 2026-10-08 03:12 UTC and 03:55 UTC; by-hand baseline on 2026-10-05.