security.txt Lint - RFC 9116 + CRA contact point

Lints security.txt against RFC 9116 and the EU Cyber Resilience Act reporting contact point that has applied since 11 September 2026. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

13 rules that decide whether a vulnerability report ever reaches you

A security consultant reviewing a disclosure contact and policy starts around $150 an hour

Buy the full version — $29

Questions people ask

What does security.txt Lint actually do?

It reads a security.txt file and applies 13 rules from RFC 9116 and the EU Cyber Resilience Act disclosure expectation. It flags a missing or expired Expires line, a Contact that is not a URI, http:// URIs, duplicated fields, a Canonical that is not the /.well-known path, a CSAF link that is not provider-metadata.json, unknown field names and unparsable lines, each on its own line number.

Who is this for?

Maintainers, platform and security engineers who ship software or connected products into the EU and own the /.well-known/security.txt file for their domain. If a stranger finding a live exploit has to guess where to send it, this file is your job, and since 11 September 2026 the Cyber Resilience Act treats it as part of your reporting duty.

Why is a free checker or a chatbot not enough?

Since 11 September 2026 the EU Cyber Resilience Act, Regulation (EU) 2024/2847 Article 14, gives you 24 hours for an early warning, 72 hours for a notification and 14 days for a final report on an actively exploited vulnerability, with fines up to 15 million euro or 2.5% of turnover. A chatbot cannot know today's date, so it will not tell you your Expires line ran out 75 days ago.

What is free and what does the full version add?

Linting the file you have open is free and complete: all 13 rules, every line, no key, no watermark, no limit on how often you run it. The full version changes the scope and the ownership. It scans every security.txt in the workspace in one pass and exports a dated JSON report you keep and attach to an audit or a customer questionnaire.

What would this cost me otherwise?

A security consultant reviewing a disclosure contact point and policy starts around $150 an hour, and the review is a snapshot that goes stale the day the Expires value passes. The extension is $29 once, runs on every save, and on the sample file in this repository it returns 9 findings from a 10-line file in under a second.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool