Security

security.txt Validator

Validate your security.txt for required fields, formatting, and best practices. Helps you publish a correct disclosure policy file.

Last reviewed by the Radiatus Cloud team

Publish at /.well-known/security.txt. Include at least Contact and Expires.

Report

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Validate your security.txt

A security.txt file tells security researchers how to report vulnerabilities in your site, and it must follow a defined format to be useful. This validator checks your security.txt for the required fields, correct formatting and best practices.

Why security.txt matters

When a researcher finds a vulnerability in your site, they need a way to tell you, and without a clear channel the report often never reaches the right person, or the researcher gives up. A security.txt file at a standard location provides that channel, listing a contact and related details in a machine-readable format. To work it must be correctly formatted, with the required fields present and valid. Validating it ensures a researcher’s tools and eyes can actually read it, which is the difference between an open door for responsible disclosure and a broken one.

An open door for disclosure

The tool runs entirely in your browser, so nothing you paste is uploaded, which is exactly what you want when the input is your own security-sensitive data.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is security.txt?

A file at a standard location that tells security researchers how to report vulnerabilities in your site, in a defined machine-readable format.

Why does it need validating?

Because it must follow the format and include the required fields to be readable by researchers’ tools and useful. Errors can make it ineffective.

What fields are required?

A contact method is essential, with other fields like an expiry date and policy link recommended. The validator checks for the required and best-practice fields.

Why offer a disclosure channel?

Because without one, vulnerability reports often never reach you and researchers give up. A valid security.txt keeps that door open.

Is my file uploaded?

No. The validation runs entirely in your browser.

Privacy & Security

Validated locally in your browser. No data is sent to any server.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your security.txt content and click Validate.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.