Official foundations
Standards bodies, official documentation and public authorities are used as primary reference points.
Authorities, guidance and security tools help prioritise risks and verify safeguards. A general alert does not prove a particular site is vulnerable; its version and configuration matter.
Inventory software, versions and sensitive journeys. For each relevant advisory, check whether the installed version and configuration are affected, then assign the fix and its verification.
Browse the resourcesEach entry has a clear role and an official destination. The catalogue avoids link farms, copied descriptions and artificial rankings.
Standards bodies, official documentation and public authorities are used as primary reference points.
Established services are grouped by actual use: building, hosting, measuring, securing, publishing or promoting a website.
Inclusion is editorial and unpaid. A listing does not imply a partnership or guarantee.
| Criterion | Question to resolve |
|---|---|
| Scope | Does the resource concern your software version and actual exposure? |
| Assessment | Is an automated score sufficient, or must access, data and logs be examined? |
| Recovery | Is there an owner, a tested backup and an incident procedure? |
Keep a short decision record: requirement, source, observed result and unresolved point. Test the same task with each candidate instead of comparing marketing lists of features.
Compare their role and documentation before selecting a tool. Inclusion is not a ranking.
50 resources displayed
No resource matches these filters. Try a broader search.
French national authority for information-system security and defense.
Use it for : Find the guidance or notice relevant to the site’s actual risk and context.
French alerts, advisories and bulletins on vulnerabilities and incidents.
Use it for : Cross-check a security notice against versions actually deployed.
French authority for personal-data protection and GDPR.
Use it for : Consult guidance matching the actual personal-data processing.
French prevention, assistance and resources against digital threats.
Use it for : Choose steps suited to the observed incident and retain the facts.
Strategic monitoring, cyber risk and digital intelligence for organisations.
Use it for : Cross-check a threat analysis with primary sources before acting.
Open references and projects for Web application security.
Use it for : Use security resources as a testing basis, not proof of compliance.
Analysis of a website’s security headers and settings.
Use it for : Review flagged headers, then test their effect on the website.
Quick check of the main HTTP security headers.
Use it for : Interpret the diagnosis against the site’s real needs and integrations.
Check whether addresses and domains appear in known data breaches.
Use it for : Use the service within internal breach-response procedures.
Cybersecurity risk-management framework for organisations.
Use it for : Map framework functions to the organisation’s responsibilities.
US alerts and resources on cyber risks and infrastructure.
Use it for : Connect relevant alerts to an inventory of software in service.
Dependency, container and code analysis for detecting vulnerabilities.
Use it for : Triage flagged dependencies by exposure, use and available fix.
Analysis of files, URLs, domains and security indicators.
Use it for : Interpret results cautiously and protect confidentiality of submitted files.
Public diagnostic of a Web server’s TLS configuration.
Use it for : Check the public domain’s TLS setup after a change.
European Data Protection Board and GDPR guidance.
Use it for : Place European guidance in the context of the data processing concerned.
Open practical guides for applying security controls to Web applications and interfaces.
Use it for : Read the sheet matching the security control being designed or checked.
Verification standard for defining and checking application-security requirements.
Use it for : Define verification requirements that fit the application scope.
Guidance from the French authority for reducing common digital risks faced by organizations and users.
Use it for : Turn relevant recommendations into assigned responsibilities and documented checks.
Official French guidance on cookies, trackers, consent and publisher responsibilities.
Use it for : Check applicable rules before choosing trackers and the consent interface.
Priority CERT-FR alerts about vulnerabilities and threats requiring prompt action.
Use it for : Compare affected products and versions with your own inventory before acting.
Official command for checking known vulnerabilities and abandoned packages in a PHP project.
Use it for : Review dependency advisories, then check applicability and available updates.
Public principles for integrating security into digital-product design and defaults.
Use it for : Review design principles when product choices shift risk onto users.
Technical guide to Content Security Policy for limiting resources and behaviors allowed in the browser.
Use it for : Prepare a policy matching resources actually loaded and inspect violations.
Awareness reference for major categories of Web application security risk.
Use it for : Use the list to orient a risk review, not as proof that a site is secure.
Project focused on API-specific risks, authorization controls and secure design practices.
Use it for : Review API risks against its access rules, exposed data and actual flows.
Catalog of vulnerabilities known to be exploited in the wild, useful for prioritizing remediation.
Use it for : Cross-reference listed exploited flaws with software actually installed.
GitHub features for inventorying dependencies, detecting vulnerabilities and automating updates.
Use it for : Review dependencies, provenance and permissions in the software delivery process.
Official PHP manual section covering configuration, user data, sessions and common risks.
Use it for : Check guidance for the PHP version and features actually used.
Official recommendations for reducing risks involving dependencies, requests and Node.js execution.
Use it for : Evaluate dependencies, runtime and configuration in the application context.
Checks selected HTTP security settings and explains the tests and their limits.
Use it for : Inspect flagged headers and test fixes without treating the grade as a complete security audit.
Automated checks of open-source project security practices, to interpret in context.
Use it for : Read detailed checks on a dependency before drawing a conclusion from its overall score.
Open vulnerability database for software packages, with searches by affected version.
Use it for : Compare an advisory with the exact package version used by the project.
European Data Protection Board resources on personal-data breaches.
Use it for : Find European regulator guidance for assessing a personal-data incident.
Official guidance on determining and documenting personal-data retention periods by purpose and applicable rules.
Use it for : Set a justified period for received enquiries, then document archiving or deletion.
Explanation of cross-origin resource sharing and related browser HTTP exchanges.
Use it for : Separate cross-origin rules from API operation permissions.
Guidance for authentication design and sensitive-operation controls.
Use it for : Connect sign-in, recovery and reauthentication to service risks.
Guidance for account recovery journeys and their checks.
Use it for : Try an expired link, absent account and completed recovery using synthetic data.
Guidance for controls determining permitted actions and resources.
Use it for : Test a direct address using a restricted account.
Guidance for session protection, management and lifecycle.
Use it for : Check expiry, logout and revoked access after a role change.
Guidance for logging events, selecting data and protecting logs.
Use it for : Use synthetic markers to detect unnecessary collection of sensitive content.
Guidance for received file checks, formats, storage and permissions.
Use it for : Check content, size, access and deletion rather than trusting only a declared type.
Guidance for REST API security, exchanges and access controls.
Use it for : Associate each operation with permissions and observable refusal cases.
Explanation of values interpreted as formulas when files are opened in spreadsheets.
Use it for : Review the receiving software and exported fields before choosing safeguards.
Guidance for application errors and separation of user information from internal diagnosis.
Use it for : Show a useful action without exposing server traces or secrets.
Guidance for password storage mechanisms and their maintenance.
Use it for : Have the security owner review storage and migrations.
Official documentation for validating GitHub webhook delivery signatures.
Use it for : Test altered payloads before permitting business operations.
Documentation for Dependabot alerts concerning known repository dependencies.
Use it for : Compare package, version and context before setting remediation priority.
Documentation for reviewing dependency changes in a GitHub repository.
Use it for : Review the origin and effect of dependencies introduced by a change.
Documentation for provenance linking npm publication to source and build.
Use it for : Read available evidence without turning it into a safety guarantee.
Reference for PHP password hashing and verification APIs.
Use it for : Use maintained APIs and have the project’s storage mechanism reviewed.
These examples illustrate uses, not rankings or endorsements. Verify each provider’s current documentation and terms before a decision.
Authorities, guidance and security tools help prioritise risks and verify safeguards. A general alert does not prove a particular site is vulnerable; its version and configuration matter.
Questions to checkA practical use : Inventory software, versions and sensitive journeys. For each relevant advisory, check whether the installed version and configuration are affected, then assign the fix and its verification.
What this cannot prove : A scanner or alert list proves neither safety nor compromise. Personal-data questions require an assessment tailored to the incident.
Related guide : Test website restoration before an incident
This non-exhaustive directory was last reviewed on 30 August 2026; its links were checked on 25 September 2026. Some websites restrict automated checks. It contains external links to independent websites. Their availability, content, prices, cookies and terms may change. Française du Numérique does not control them and receives no commission for their inclusion.