Is your website safe? Find out in a minute.

Our AI agents go at your site like a real attacker, check if it’s already been hacked and explain every fix in words you actually understand. Every week.

alderfinch.exampleEXAMPLE · FULL REPORT
Checked 16 September
3
things to fix on your website
One of them hands out the password to your database.
Needs attention

A backup of your site’s settings is public

Anyone can download it, and it holds the password to your database, where your orders live.

about 10 min

Two plugins have publicly known holes

Attackers scan for these two automatically. Both already have a safe update waiting.

about 5 min

Anyone can send email in your name

Your domain lets strangers write to your customers as if the message came from you.

about 15 min
A yearly audit
1 check a year
Teyna
52 checks a year

Safe to point at production by design.

Teyna runs against the real thing, on purpose. The limits that make that safe are written into the software, not into a promise.

It cannot take your site down

It only reads — never changes, deletes or submits anything — and stays quieter than a slow evening of real customers.

It never takes your customers' data

It keeps the smallest piece of evidence that proves the problem, and masks anything that looks like a password.

It has to prove itself before it speaks

Every problem is proved twice before you are told. What it cannot prove, it says so instead of guessing.

It goes deeper only when you let it

The first run only reads what is already public. Anything deeper happens after you turn it on inside your dashboard, and stops the moment you turn it off.

What happens when nobody checks.

None of these arrive with a warning. You hear about them from a customer, a bank or Google.

yourbusiness.com
Deceptive site ahead

Google warns your visitors away

Browsers show a red “deceptive site” screen before anyone reaches your page.

Campaign · Spring saleSuspended
ReasonCompromised site

Your ads stop running

Ad networks suspend accounts that send traffic to a compromised site.

Card number4242 •••• ••••
cdn-metrics.example

Card numbers leave from your checkout

One swapped script copies what customers type and sends it somewhere else.

Your order is readySpam
from you@yourbusiness.comunverified

Your email lands in spam

Once anyone can send mail as you, providers stop trusting your domain.

Why not a free online scanner?

You have probably tried one already. Here is the same site through both.

free-scanner.example214 warnings
INFOMissing X-Frame-Options header
LOWServer version disclosed: nginx/1.24.0
HIGHPossible CVE-2021-44228 (Log4Shell)
LOWCookie without Secure flag
INFOTRACE method may be enabled
MEDDirectory listing possibly enabled: /assets/
INFOjQuery 3.5.1 detected
LOWContent-Security-Policy not set
MEDClickjacking possible
LOWAutocomplete enabled on password field
LOWHSTS max-age below recommended
INFOETag may leak inode numbers
MEDWordPress version may be outdated
INFOrobots.txt reveals /wp-admin/
LOWReferrer-Policy not set
HIGHPossible SQL injection in ?page=
INFOPermissions-Policy not set
LOWTLS 1.0 may be accepted
MEDPossible open redirect in ?next=
INFOEmail address found in page source
LOWX-Powered-By header present
INFOMixed content check inconclusive
INFOMissing X-Frame-Options header
LOWServer version disclosed: nginx/1.24.0
HIGHPossible CVE-2021-44228 (Log4Shell)
LOWCookie without Secure flag
INFOTRACE method may be enabled
MEDDirectory listing possibly enabled: /assets/
INFOjQuery 3.5.1 detected
LOWContent-Security-Policy not set
MEDClickjacking possible
LOWAutocomplete enabled on password field
LOWHSTS max-age below recommended
INFOETag may leak inode numbers
MEDWordPress version may be outdated
INFOrobots.txt reveals /wp-admin/
LOWReferrer-Policy not set
HIGHPossible SQL injection in ?page=
INFOPermissions-Policy not set
LOWTLS 1.0 may be accepted
MEDPossible open redirect in ?next=
INFOEmail address found in page source
LOWX-Powered-By header present
INFOMixed content check inconclusive
Showing 22 of 214 · sorted by nothing · export CSV
Which of these is real? Which one first? You are on your own.
Teyna · your report3 to fix
A backup of your site’s settings is public

Delete one file, change one password.

Two plugins have publicly known holes

Press Update next to both, about 5 minutes.

Anyone can send email in your name

Add two records, we give you the exact text.

211 set aside · each with the reason it was not real
Real problems only, worst first, each with what to do.

No security team. No jargon. Fifteen minutes.

What it looks like for a small business on an ordinary morning.

09:12

Paste the address

One button. A minute later the report says two things need fixing, worst first.

09:14

Ask what it means

“What do I do?” The AI explains it the way a person would, and gives three steps.

09:31

Done, and confirmed

You follow the steps. Teyna checks again and confirms it is really closed.

Start free. Pay when you want it watched

The first check costs nothing and needs no card. Paid plans keep checking after you've fixed things, because websites change every week.

Nothing found in your first month? It’s refunded.

If your first paid month turns up nothing worth fixing, we refund it automatically — and you keep the report, a dated answer for whoever asked.

Free check
The outside check, proven and explained in plain words
$0
Signs your site has already been hacked
The padlock, security settings and email protection
Open pages, backups and forgotten copies
Results in your dashboard — no card, no install
Recommended
Starter
One website, checked every week. One website means one domain and every subdomain we find on it.
$59per month
The full check, not just the outside
Step-by-step fixes for every problem
A prompt you can hand to your AI assistant
An email only when something new appears
Pro
Up to five websites and the code behind them
$179per month
Everything in Starter, for five sites
Your repositories, commit history included
Reports under your own name
A section for the paperwork auditors ask for
Your checks jump the queue

Swipe to compare plans

Cancel whenever you like — the next month simply doesn't start.

One run, four reports.

The same findings, written for whoever has to read them.

3
for you

What to fix first

Three sentences per problem: what could happen, how bad it is, and what to do about it.

GET /setup→ 200 OK- apiKey: sk_live_••••+ apiKey: env
for your developer

The technical detail

Request, response, the exact line, the proof it was repeated, and the change to make.

✓ Checked16 Sep 2026
for your client

Proof it was checked

A dated summary you can forward under your own name, without exposing your stack.

for an auditor

The whole record

Every finding, every re-check and every authorisation, dated and in one place.

See the example report ↑

Watch the machine work. Three views of one night.

You never need any of this to use Teyna. It is here for the curious, and for your developer.

Inside a single run of the machine.

Most of it you never see: hundreds of raw results become the handful that could actually be used against you.

The limits it works inside
Run 4f82c116 Sep · 03:00–03:38
Signal space312 → 3
what this means for you

While you slept, it went over your site from every side, threw out the false alarms and kept the three problems that are real. You never had to read any of it.

Watch it think its way in

A break-in is never one mistake. You see every link in the chain, in order.

How it stays safe doing that
Attack surface5 hosts · 1 repository
The path it found16 Sep · 03:29
A new address appearedautomations…

Nobody told you about it. It showed up in a public certificate log on 14 September.

It answers the whole internetport 443 open

No password, no restriction on who can reach it.

It is still on its first-run screen/setup → 200

The screen that asks who the owner should be, waiting since September.

Whoever finishes it owns the machineruns commands

The owner of this tool can run commands on the server it sits on.

A stranger becomes the owner and runs commands on your server, without ever guessing a password.
Start free →
what this means for you

One forgotten page was enough for a stranger to take over your server. Teyna found it before anyone else did, and told you which door to close first.

It reads your code, too

Connect the repository and it reads that too: passwords in the code, keys still working, packages with known holes.

What's included
apps/api/src/mailer.tsEXAMPLEmain
7import { createTransport } from 'nodemailer'
8
9export const mailer = createTransport({
10  apiKey: 'sk_live_••••••••••••4f2a',
10+  apiKey: process.env.MAIL_API_KEY,
11  host: 'smtp.alderfinch.example',
12})
This key is written straight into your code

It has been in the repository since a commit made 14 months ago, and it still works. Anyone who can read the code can send mail as you — replace it with a setting, then retire the old key.

RepositoryEXAMPLEfernhill-studio/alderfinch-wp
1 password left in the code
Mail key, still valid · committed 14 months ago
fix
2 packages with known holes
Both have a safe version out · one line each
fix
Settings file kept out of the build
Checked, nothing exposed
ok
No keys in the commit history
Besides the one above · 4,812 commits read
ok
Read-only access, code and history only. Teyna never writes to your repository and never opens a pull request without you.
what this means for you

A password left in your code 14 months ago still worked. Teyna found it, showed exactly where it is, and wrote the fix for you or your AI to apply.

Questions before the first run

What happens after I click “Scan my site”?

You confirm your email and land in your dashboard while the first run finishes, which takes about a minute. You see what was found in plain words, worst first. Nothing to install, and no card.

Can it tell if my site has already been hacked?

It shows the signs you can see from outside: hidden scripts on your pages, spam pages Google sees but you don’t, strange redirects, and whether your site is on a blocklist. It can’t see inside your server, so a clean result is not a guarantee, and it does not clean the site for you. If it finds signs of a hack, it tells you exactly what to do first.

Will my host or Wordfence block the check?

Usually not. Teyna is gentle, only reads, and signs every request with its own name, so it is easy to recognise. If your host does block it, we tell you and show how to let it through.

How is this different from Wordfence or a security plugin?

A plugin watches from inside WordPress. Teyna looks from outside, the way an attacker does: forgotten copies, open backups, your email, parts of your site the plugin never sees. The two work well together.

Can I check my clients’ sites?

Yes. Put every client site in one list on Pro and send reports under your own name. Need more than five? You add them from your dashboard.

What if my site turns out to be fine?

If your first paid month finds nothing worth fixing, that month is refunded automatically, and you keep the report — a dated record that your site was checked and nothing was found. That is the answer you want when a client, a bank or an insurer asks.

I don't know anything about security. Will I understand the report?

That's who it's written for. Each problem is one sentence about what could happen to you, then the steps to stop it. No codes, no jargon. If a fix needs a developer, we say so instead of pretending you can do it.

I don't have a developer. What then?

Most fixes are settings you change yourself in 5 to 20 minutes, and the steps say exactly where to click. For the rest you can copy a ready-made prompt and give it to an AI assistant like Cursor, Claude or ChatGPT, or forward the whole list to whoever built your site.

How long does it take?

The free run takes about a minute and appears on screen. The full run happens overnight and is waiting for you the next morning — it's deliberately slow and gentle so your site never feels it.

Is this legal? I've heard scanning websites isn't allowed.

The free run only reads what anyone on the internet can already see, the same way a search engine does. Anything deeper is switched on by you, on your own site, inside your dashboard.

What do you do with what you find?

It's yours. We keep the report so you can compare it with the next one, we don't sell it, and we don't publish anything about your site. Delete your account and the reports go with it.

My site is on WordPress, Shopify, Wix or Webflow. Does that work?

Yes. Teyna checks the site the way the public sees it, so it doesn't matter what it was built with. On hosted builders some fixes are settings in your account, and the steps are written for that.

Can Teyna check a server, not just a website?

Yes. Type the server’s IP address into the same field instead of a web address. Teyna checks what that server shows to the internet: which doors are open, what software answers behind them, and whether that software has known holes. The padlock and email checks need a web address, so for a website you get the fullest report by typing its address.

Find out tonight, not after something happens

Enter the address and the run starts. Results land in your dashboard.

For online shops, small businesses, web studios and anyone shipping with AI. No security team needed.

what the first minute covers
  • Signs your site has already been hacked
  • The padlock and your site’s security settings
  • Protection against fake email in your name
  • Open pages, backups and forgotten copies
  • Plugins and software that need updating