Security

Only modern encryption is accepted

security.legacy-tls

Why this matters

TLS 1.0 and 1.1 are obsolete encryption standards with known weaknesses. Modern browsers refuse them anyway, so leaving them switched on gains you nothing and leaves a weaker option available to anything that asks for it.

Who fixes it

A developer

Roughly how long

Varies

Care needed

Test before and after

How to fix it

Set the minimum protocol to TLS 1.2 in your server or CDN configuration. Most hosting panels expose this as a single setting.

How we score it

Failing this check takes up to 12 points off your security score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.

Does your site pass this one?

This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.

Check my site

Other security checks

See all 107 checks