Vigavo for Webflow
Your Webflow site, checked.We stay awake.
Webflow hosts the site. We check what you control: email DNS, your domain, custom code and the integrations you embedded.
Free. No signup. Read-only checks from the outside.
What Vigavo checks on your Webflow site
Custom code in page settings and embeds runs for every visitor. We look for keys and tokens that should never be public.
Security check
Exposed keys in your custom code and embeds, email spoofing protection, domain expiry, risky subdomains, blacklists and mixed content.
Change alerts
We re-check on a schedule and tell you when something new appears, by email, Telegram, Slack or webhook.
An honest grade
Settings that Webflow controls are shown separately and never lower your grade.
Managed by Webflow
Webflow runs the servers: security headers, TLS certificates, server software and compression are set by Webflow for every site. Your report lists them under "Managed by Webflow" so you know what they are, without asking you to fix them.
What you can fix
- ✓ Email DNS: SPF, DKIM and DMARC so nobody can send mail as you
- ✓ Your domain: renewal date, transfer lock, subdomains
- ✓ Content: search visibility, link previews, broken links
- ✓ Third-party apps, scripts and embeds you added
Tip: form and CMS integrations often use API keys; keep them in a server-side automation, not in page code.
Questions
Why don't missing security headers lower my grade on Webflow?
Webflow sets them for every site it hosts and gives you no way to change them. We show them under "Managed by Webflow" and grade only what you can influence.
Do I need to install anything on Webflow?
No. Paste your address and the check runs from the outside, like a visitor's browser. Nothing is added to your Webflow site.
What happens when something changes?
We compare every scan with the previous one and alert you about new issues. If Webflow changes a security setting on its side, you get one short notice.
Is the scan safe for my site?
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
Other platforms