Vigavo for Squarespace
Your Squarespace site, checked.We stay awake.
Squarespace runs the servers. We check what you control: email DNS, your domain, code injection and the third-party blocks you added.
Free. No signup. Read-only checks from the outside.
What Vigavo checks on your Squarespace site
Code injection and code blocks are where owners add tracking and widgets; that is also where keys and outdated scripts show up.
Security check
Exposed keys in your custom code and embeds, email spoofing protection, domain expiry, risky subdomains, blacklists and mixed content.
Change alerts
We re-check on a schedule and tell you when something new appears, by email, Telegram, Slack or webhook.
An honest grade
Settings that Squarespace controls are shown separately and never lower your grade.
Managed by Squarespace
Squarespace runs the servers: security headers, TLS certificates, server software and compression are set by Squarespace for every site. Your report lists them under "Managed by Squarespace" so you know what they are, without asking you to fix them.
What you can fix
- ✓ Email DNS: SPF, DKIM and DMARC so nobody can send mail as you
- ✓ Your domain: renewal date, transfer lock, subdomains
- ✓ Content: search visibility, link previews, broken links
- ✓ Third-party apps, scripts and embeds you added
Tip: if your domain is registered elsewhere, its renewal and DNS records are yours to keep in order.
Questions
Why don't missing security headers lower my grade on Squarespace?
Squarespace sets them for every site it hosts and gives you no way to change them. We show them under "Managed by Squarespace" and grade only what you can influence.
Do I need to install anything on Squarespace?
No. Paste your address and the check runs from the outside, like a visitor's browser. Nothing is added to your Squarespace site.
What happens when something changes?
We compare every scan with the previous one and alert you about new issues. If Squarespace changes a security setting on its side, you get one short notice.
Is the scan safe for my site?
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.